Implicit Rules; Implicit Filter Rules; Rule Table - Stormshield SN series Configuration Manual

Hide thumbs Also See for SN series:
Table of Contents

Advertisement

IMPLICIT RULES

Implicit filter rules

This screen shows that it is possible to automatically generate various IP filter rules in order to
allow the use of some of the firewall's services. If a service is enabled, the firewall will
automatically create the necessary filter rules, without having to create "explicit" rules in the filter
policy.

Rule table

The table contains the following columns:
On
Name
The following rules appear in the "Name" column:
Allow interfaces associated with authentication profiles (Authd) to access the
l
authentication portal and the SSL VPN: a rule allowing access to the https service (port 443)
will be created for each interface associated with an authentication profile that has enabled
the captive portal. Users can then authenticate and access the SSL VPN from the networks
corresponding to these interfaces.
Block and reinitialize ident requests (port 113) for modem interfaces (dialup).
l
Block and reinitialize ident requests (port 113) for ethernet interfaces.
l
Allow protected interfaces to access the firewall's DNS service (port 53) : users can
l
contact the DNS service and therefore use the DNS cache proxy if it has been enabled.
Allow mutual access to the administration server (port 1300) between the members of a
l
firewall cluster (HA) : this allows the different members of the HA cluster to communicate
with each other.
Allow access to the PPTP server: users can contact the firewall via PPTP to access the server,
l
if it has been enabled.
Allow protected interfaces (serverd) to access the firewall's administration server (port
l
1300): administrators will be able to log on via their internal networks to port 1300 on the
firewall. This service is used especially by Stormshield Network Real-Time Monitor.
Allow protected interfaces to access the firewall's SSH port: allows opening access to the
l
firewall via SSH in order to log on using command lines from a host located on the internal
networks.
Page 158/448
Status of the rule:
Enabled/
Disabled: Click on the field to enable/disable the creation of one or
several implicit riles.
The rule Allow external (unprotected) interfaces (Authd_ext) to access the
authentication portal and the SSL VPN has been disabled by default.
Name of the implicit rule: this name cannot be modified.
SNS - USER CONFIGURATION MANUAL V.3
sns-en-user_configuration_manual-v3 - Copyright © Stormshield 2016
IMPLICIT RULES

Hide quick links:

Advertisement

Table of Contents
loading

Table of Contents