D-Link DFL-1000 [37/168] Configuring policy lists

D-Link DFL-1000 [37/168] Configuring policy lists
DFL-1000 User Manual
3
7
Adding a Transparent mode Int -> Ext policy
Configuring policy lists
The firewall matches policies by searching for a match starting at the top of the policy list and moving
down until it finds the first match. You must arrange policies in the policy list from more specific to more
general.
For example, the default policy is a very general policy because it matches all connection attempts. When
you create exceptions to this policy, you must add them to the policy list above the default policy. No
policy below the default policy will ever be matched.
This section describes:
Policy matching in detail
Changing the order of policies in a policy list
Enabling and disabling policies
Policy matching in detail
When the DFL-1000 NPG receives a connection attempt at an interface, it must select a policy list to
search through for a policy that matches the connection attempt. Each interface has two policy lists (for
example, the two external interface policy lists are Ext
->
Int and Ext
->
DMZ). The DFL-1000 NPG
chooses the policy list based on the destination address of the connection attempt.
The DFL-1000 NPG then starts at the top of the selected policy list and searches down the list for the first
policy that matches the connection attempt source and destination addresses, service port, and time and

Содержание

Скачать