Configuring Firewall Rule Options; Enabling Nat - Juniper NETWORK AND SECURITY MANAGER 2010.4 - ADMININISTRATION GUIDE REV1 Administration Manual

Table of Contents

Advertisement

Network and Security Manager Administration Guide

Configuring Firewall Rule Options

454
To see the exact rules that are applied to a specific device, in Device Manager, right-click
a device and select Policy > View Pending Device Policy.
NOTE: If a device specified in the Install column does not support a specific
rule option configured for the rule, you can still install the security policy on
the device, but the rule option is not enabled for that device. Additionally,
during policy validation, a warning appears for each unsupported rule option.
For details, see "Validating Security Policies" on page 509.
Rule options enable you to configure additional protection mechanisms and other
miscellaneous features. You can configure the following rule options:
Enabling NAT on page 454
Enabling GTP for Firewall Rules on page 455
Configuring Traffic Shaping in a Security Policy on page 455
Enabling Logging and Counting for Firewall Rules on page 457
Miscellaneous on page 458
ID on page 459
Configuring Web Filtering for Firewall Rules on page 460
Configuring Authentication for Firewall Rules on page 461
Configuring Antivirus for Firewall Rules on page 462
Configuring a DI Profile/Enable IDP for Firewall Rules on page 463
Configuring the Session Close Notification Rule on page 465
To quickly configure all rule options, right-click the Rule Options column and select
Configure All Options. The Configure Options dialog box appears; select the option tab
you want to configure for the rule.

Enabling NAT

You can configure a policy-based network address translation (NAT) for a firewall rule.
NAT enables the security device to translate the IP address of incoming or outgoing traffic
so that the packets are routeable on the network.
Edit Source NAT
You can configure the security device to translate the source IP address:
To translate the source IP address using a predefined range of IP addresses, select
NAT and choose a Dynamic IP pool (DIP) object. For each matching packet, the device
translates the original source address into a IP address selected from the DIP pool.
To translate the source IP address using the IP address of the outgoing interface on
the security device, select Use Interface.
Copyright © 2010, Juniper Networks, Inc.

Advertisement

Table of Contents
loading

This manual is also suitable for:

Network and security manager 2010.4

Table of Contents