Customizing The Firewall; Definitions - Secure Computing SG300 User Manual

Snapgear gateway
Hide thumbs Also See for SG300:
Table of Contents

Advertisement

Select the appropriate Country and certificate key length from the Generate an RSA key
of pull-down menu. All other fields but Host name (Common Name) are optional; they
are used to create the certificate's distinguished name.
Generating a certificate usually takes a few minutes, exact time depends on the model of
SnapGear unitand the key length. When the certificate has been created, A valid SSL
certificate has been installed is displayed under the Web Server tab.

Customizing the Firewall

The majority of firewall customization is typically accomplished by creating Packet Filter
and network address translation (NAT) rules.
Packet filter rules match network packets based on a combination of incoming and
outgoing interface, source and destination address and destination port and protocol.
Once a packet is matched, it can be allowed or disallowed.
NAT rules match packets in a similar manner. However, instead of simply allowing or
disallowing traffic, you may alter the source or destination address and/or port of the
packet as it passes through the firewall.
A typical use of NAT rules is to forward packets destined for your Internet IP address to
an internal web server or email server on your LAN. This is known as a port forward or
destination NAT, as it alters the destination address of the packet.
The first step in creating packet filter or NAT rules is to define services (such as web or
email) and addresses (such as your internal web server, or a trusted external host) under

Definitions.

Definitions
Before creating packet filter or NAT rules, it is sometimes useful to define services or
groups of services, addresses and interfaces to be used to match packets.
Definitions need not be created for simple rules that only specify a single service,
address or interface, as these can be entered while creating the rule.
If a rule specifies groups of services, addresses or interfaces, then you must create
definitions for these groups before creating the rule.
Firewall
140

Hide quick links:

Advertisement

Table of Contents
loading

This manual is also suitable for:

Sg530Sg570Sg575Sg580Sg550Sg560 ... Show all

Table of Contents