D-Link DFL-1000 [34/168] Arrange policies in the policy list so that they have the results that you expect arranging policies in a policy list is described in configuring policy lists

D-Link DFL-1000 [34/168] Arrange policies in the policy list so that they have the results that you expect arranging policies in a policy list is described in configuring policy lists
DFL-1000 User Manual
34
example, the policy for the corporate web server might be given higher priority than the
policies for most employees' computers. An employee who needs unusually high-speed
Internet access could have a special outgoing policy set up with higher bandwidth.
Guaranteed
Bandwidth
You can use traffic shaping to guarantee the amount of bandwidth available through the
firewall for a policy. Guarantee bandwidth (in kbps) to make sure that there is enough
bandwidth available for a high-priority service.
Maximum
Bandwidth
You can also use traffic shaping to limit the amount of bandwidth available through the firewall
for a policy. Limit bandwidth to keep less important services from using bandwidth needed for
more important services.
Traffic
Priority
Select High, Medium, or Low. Select Traffic Priority so that the DFL-1000 NPG manages the
relative priorities of different types of traffic. For example, a policy for connecting to a secure
web server needed to support e-commerce traffic should be assigned a high traffic priority.
Less important services should be assigned a low priority. The firewall provides bandwidth to
low-priority connections only when bandwidth is not needed for high-priority connections.
Log Traffic
Select Log Traffic to write messages to the traffic log whenever the policy processes a
connection.
Authentication
Select Authentication and select a user group to require users to enter a user name and
password before the firewall accepts the connection. Select the user group to control the
users that can authenticate with this policy. To add and configure user groups, see Users and
authentication. You must add user groups before you can select Authentication.
You can select Authentication for any service. Users can authenticate with the firewall using
HTTP, Telnet, or FTP. For users to be able to authenticate you must add an HTTP, Telnet, or
FTP policy that is configured for authentication. When users attempt to connect through the
firewall using this policy they are prompted to enter a firewall username and password.
If you want users to authenticate to use other services (for example POP3 or IMAP) you can
create a service group that includes the services for which you want to require authentication
as well as HTTP, Telnet, and FTP. Then users could authenticate with the policy using HTTP,
Telnet, or FTP before using the other service.
In most cases you should make sure that users can use DNS through the firewall without
authentication. If DNS is not available users cannot connect to a web, FTP, or Telnet server
using a domain name.
Web filter
Enable web filter content filtering for traffic controlled by this policy. You can select Web filter
if Service is set to ANY, HTTP, SMTP, POP3, or IMAP, or to a service group that includes the
HTTP, SMTP, POP3, or IMAP services.
For web filter content filtering to take effect, you must configure web content filtering. See
Web content filtering
.
You can select show settings to display the current web filter content filtering settings for the
DFL-1000 NPG.
Select OK to add the policy.
Arrange policies in the policy list so that they have the results that you expect.
Arranging policies in a policy list is described in Configuring policy lists
.

Содержание

Скачать