305
DMZ (low)
If internet servers are kept in a separate physical network, this network is called a
demilitarized zone (DMZ). This is the typical use case of this option. Particularly
the LAN networks have unlimited access to servers in the DMZ. In contrast,
internet access to the DMZ has to be allowed on tab "* > SX-GATE >
To restrict DMZ access for the LAN networks, can change
the corresponding setting on tab "General".
RAS (medium)
By and large, the default policy activated by this option is comparable to "LAN
(high)". However it is possible to limit connections from the respective networks to
all destinations. With "LAN (high)" only connections to the Internet are restricted.
LAN (high)
Choose this option to activate the least restrictive policy. By default only direct
internet access is limited for the respective networks. Access to all other types
of interfaces is granted. To impose limitations here, change to the option "RAS
(medium)".
14.2.2-A
General
Description "
…
"
This field serves for documentation only.
Default policies
The following table shows and partly even lets you alter the firewall default policy. The
defaults depend on the actual zone this interface is in. For the zone assignment, please
see option "Classification (Trustlevel)".
14.2.2-B
DNAT > *
On this tab you define portforwarding rules (DNAT). DNAT modifies the destination IP
of a connection. This allows for example to establish a direct connection to a server
with an internal IP address from the Internet. DNAT rules have to be specified in the
connection's incoming interface.
Содержание SX-GATE
Страница 1: ...State 2016 12 13 V7 0 2 0 User Guide ...
Страница 92: ...12 1 Setup 92 There s no way to restore a purchased certificate without backup ...
Страница 126: ...12 3 3 Groups 126 12 3 3 C Usage This table show in which settings the definition is used ...
Страница 476: ...15 3 Apple iPhone 476 ...