Configuring Firewall Rule Options; Enabling Nat - Juniper NETWORK AND SECURITY MANAGER 2010.2 - ADMINISTRATION GUIDE REV1 Administration Manual

Table of Contents

Advertisement

Network and Security Manager Administration Guide

Configuring Firewall Rule Options

444
NOTE: If a device specified in the Install column does not support a specific rule option
configured for the rule, you can still install the security policy on the device, but the rule
option is not enabled for that device. Additionally, during policy validation, a warning
appears for each unsupported rule option. For details, see "Validating Security Policies"
on page 498.
Rule options enable you to configure additional protection mechanisms and other
miscellaneous features. You can configure the following rule options:
Enabling NAT on page 444
Enabling GTP for Firewall Rules on page 445
Configuring Traffic Shaping in a Security Policy on page 445
Enabling Logging and Counting for Firewall Rules on page 447
Miscellaneous on page 448
ID on page 449
Configuring Web Filtering for Firewall Rules on page 450
Configuring Authentication for Firewall Rules on page 451
Configuring Antivirus for Firewall Rules on page 452
Configuring a DI Profile/Enable IDP for Firewall Rules on page 453
Configuring the Session Close Notification Rule on page 454
To quickly configure all rule options, right-click the Rule Options column and select
Configure All Options. The Configure Options dialog box appears; select the option tab
you want to configure for the rule.

Enabling NAT

You can configure a policy-based network address translation (NAT) for a firewall rule.
NAT enables the security device to translate the IP address of incoming or outgoing traffic
so that the packets are routeable on the network.
Edit Source NAT
You can configure the security device to translate the source IP address:
To translate the source IP address using a predefined range of IP addresses, select
NAT and choose a Dynamic IP pool (DIP) object. For each matching packet, the device
translates the original source address into a IP address selected from the DIP pool.
To translate the source IP address using the IP address of the outgoing interface on
the security device, select Use Interface.
Copyright © 2010, Juniper Networks, Inc.

Advertisement

Table of Contents
loading

This manual is also suitable for:

Network and security manager 2010.2

Table of Contents