Adding Rulebases; Configuring Firewall Rules - Juniper NETWORK AND SECURITY MANAGER 2010.3 - ADMINISTRATION GUIDE REV1 Administration Manual

Table of Contents

Advertisement

Network and Security Manager Administration Guide

Adding Rulebases

Configuring Firewall Rules

442
NOTE: If you do not have appropriate access-control permission and you attempt to
create a policy, the wizard returns an error message stating that you do not have access
to create rulebases.
In this example, you create a standalone IDP security policy that logs all levels of attack
(Critical, Major, Minor, Warning, and Info) but drops connections only for critical and
major attacks.
Click Policies, then go to the File menu and select New Policy.
1.
Give the policy a name and add comments (optional), then click Next.
2.
Select Create New Policy for (the default selection). Uncheck Firewall/VPN Devices
3.
and check Stand Alone IDP Devices, then click Next.
Select Configure IDP Policy, then click Next.
4.
Check the boxes and select Enable Logging for all attack levels. Select Drop
5.
Connection for critical and major attacks. Click Next twice to continue.
Select the device to which you want to assign this policy, then click Next.
6.
Click Finish.
7.
Security policies start with a minimum of rules and rulebases. You can add additional
rules to the rulebases as needed.
To add a rulebase:
In the main navigation tree, select Policies, then double-click the policy name in the
1.
Security Policies window.
Click the Add icon in the upper right corner of the Policy window and select Add
2.
<name> Rulebase. The rulebase tab appears.
Configure a rule in the rulebase by clicking the Add icon on the left side of the Security
3.
Policy window. A default rule appears.
Add a new rulebase by clicking the Add icon in the upper right corner of the Security
4.
Policy window, then select the rulebase you want to add from the menu. You cannot
add a rulebase more than once, so only rulebases that are not already in the policy
are displayed.
The following sections explain how to configure rules in each rulebase.
The firewall rulebases enable you to create zone and global firewall rules that control
the flow of traffic on your network. You can configure the following settings for a firewall
rule:
Copyright © 2010, Juniper Networks, Inc.

Advertisement

Table of Contents
loading

This manual is also suitable for:

Network and security manager 2010.3

Table of Contents