Configuring Packet Filter Rules
Packet Filter rules let you control traffic based on a particular
service, source IP address, or destination IP address. You define
the rules required to secure your network with the Policy Objects
--services, addresses, screen, time, proxy users.
Defining Rules
The Rule Definition dialog lets you add or modify packet filtering rules. Use the
fields in the dialog to enter the configuration information for the rule.
-
Rule Index (Optional) Assigns a number to a rule. By default, this field
displays a number one greater than the last rule (indicating
this rule will be placed bottom of the list). If you type a
lower number, the new rule will be inserted into the specified
position in the list, and the rules currently in the
configuration will be renumbered.
-
Screen (Optional) Specifies the Screen for which you want the rule to apply. Enter
a specific Screen name in this field if you use centralized management and want a rule to
apply to a specific Screen.
-
Service Specifies a service.
-
Source Address Specifies a source address. You can use the Description field to
enter notes about the address.
-
Destination Address Specifies a destination address. You can use the Description field to
enter notes about the address.
-
Action Specifies an action to apply to the
rule.
-
Time (Optional) Specifies when the rule applies.
-
Description (Optional) Notes a short description of the rule.
Action
Allow
ALLOW displays the following controls.
-
Log Sets logging behavior.
-
SNMP Specifies whether the Screen should issue an SNMP
trap message when the rule is applied.
-
PROXY Defines a proxy rule.
Deny
DENY displays the following controls.
-
Log Sets logging behavior.
-
SNMP Specifies whether the Screen should issue an SNMP
trap message when the rule is applied.
-
ICMP Reject Specifies the ICMP rejection message the
Screen sends when the rule is applied.
-
PROXY Defines a proxy rule.
Encrypt
ENCRYPT displays the following controls.
-
Log Sets logging behavior.
-
SNMP Specifies whether the Screen should issue an SNMP
trap message when the rule is applied.
-
Encryption Specifies version of SKIP.
-
Source Tunnel Specifies tunnel address of the from encryptor.
-
Destination Tunnel Specifies tunnel address of the to encryptor.
-
From Encryptor Specifies the certificate name for the machine that
is encrypting the data.
-
To Encryptor Specifies the certificate name for the machine that
is decrypting the data.
-
Key Algorithm Specifies the key encryption algorithms supported for
SKIP version 1.
-
Data Algorithm Specifies the data encryption algorithms
supported for SKIP version 2.
-
MAC Algorithm Specifies the MAC (authentication) algorithms
supported for manual keying.
Secure
SECURE allows the specified service to be encrypted and creates a tunnel between
VPN gateways. The following controls are displayed.
-
Log Sets logging behavior.
-
SNMP Specifies whether the Screen should issue an SNMP
trap message when the rule is applied.
-
VPN Specifies the name of the VPN to which the rule applies.