Watchguard Firebox X5-W Betriebsanweisung Seite 98

  • Herunterladen
  • Zu meinen Handbüchern hinzufügen
  • Drucken
  • Seite
    / 234
  • Inhaltsverzeichnis
  • FEHLERBEHEBUNG
  • LESEZEICHEN
  • Bewertet. / 5. Basierend auf Kundenbewertungen
Seitenansicht 97
Configuring Firewall Settings
82 Firebox X Edge e-Series
Filter incoming traffic for a custom service
These steps restrict incoming traffic for a service to specified computers behind the firewall. Refer to the
subsequent section for information on controlling outgoing traffic.
1 From the Incoming Filter drop-down list, select Allow or Deny.
2 If you set the Incoming Filter to Allow, type the IP address of the service host. This is the computer
that receives the traffic.
To allow incoming traffic from the external network without restrictions, skip to step 8.
3 If you redirect the service to another port, type the port number in the text box adjacent to Port
Redirect.
For more information, see “Working with Firewall NAT” on page 97.
4 To limit incoming traffic from the external network to the service host, use the drop-down list to
select Host IP Address, Network IP Address, or Host Range.
5 In the address text boxes, type the host or network IP address, or type the range of IP addresses that
identify the computers on the external network that can send traffic to the service host.
Type Network IP addresses in “slash” notation (also known as CIDR or Classless Inter-Domain Routing notation).
For more information on entering IP addresses in slash notation, see this FAQ:
http://www.watchguard.com/support/advancedfaqs/general_slash.asp
6 Click Add. The From box shows the host range, host IP address, or network IP address that you
typed.
Repeat steps 3-5 until all of the address information for this custom service is set. The From box can have more than
one entry.
7 If this service is only for incoming traffic, keep the outgoing filter set to No Rule.
To limit which computers can send information using this service, go to the subsequent section, “Filtering outgoing
traffic for services.”
8 Click Submit.
Filter outgoing traffic for a custom service
These steps restrict outgoing traffic through the Firebox X Edge. Refer to the previous section for infor-
mation on filtering incoming traffic.
1 From the Outgoing Filter drop-down list, select Allow or Deny.
To allow all outgoing traffic from the trusted or optional network to the external network using this service, skip to
step 9.
2 To limit which computers on the trusted or optional network can send traffic to the external
network using this service, use the drop-down list below the From box to select Host IP Address,
Network IP Address, or Host Range.
To only limit which computers receive information, skip to step 5.
3 In the adjacent text boxes, type the host or network IP address, or type the range of IP addresses
that identify the computers on the trusted or optional network that can use this service to send
traffic to the external network.
Network IP addresses must be entered in “slash” notation (also known as Classless Inter Domain Routing or CIDR
notation). For more information on entering IP addresses in slash notation, see this FAQ:
http://www.watchguard.com/support/advancedfaqs/general_slash.asp.
4 Click Add. The From box shows the IP addresses you added.
Repeat steps 2-4 until all of the address information for this custom service is set. The From box can have more than
one entry.
5 To limit which computers on the external network can receive network traffic with this service, use
the drop-down list below the To box to select Host IP Address, Network IP Address, or Host
Range.
Seitenansicht 97
1 2 ... 93 94 95 96 97 98 99 100 101 102 103 ... 233 234

Kommentare zu diesen Handbüchern

Keine Kommentare