D-Link DFL-1000 [38/168] Addresses

D-Link DFL-1000 [38/168] Addresses
DFL-1000 User Manual
3
8
date at which the connection attempt was received. The first policy that matches is applied to the
connection attempt. If no policy matches, the connection is dropped.
The default policy accepts all connection attempts from the internal network to the Internet. From the
internal network, users can browse the web, use POP3 to get email, use FTP to download files through
the DFL-1000 NPG, and so on. If the default policy is at the top of the Int -> Ext policy list, the firewall
allows all connections from the internal network to the Internet because all connections match the default
policy.
A policy that is an exception to the default policy, for example, a policy to block FTP connections, must be
placed above the default policy in the Int -> Ext policy list. In this example, all FTP connection attempts
from the internal network would then match the FTP policy and be blocked. Connection attempts for all
other kinds of services would not match with the FTP policy but they would match with the default policy.
Therefore, the firewall would still accept all other connections from the internal network.
Policies that require authentication must be added to the policy list above matching policies that do not;
otherwise, the policy that does not require authentication is selected first.
Changing the order of policies in a policy list
Go to Firewall > Policy .
Select the tab for the policy list that you want to rearrange.
Choose a policy to move and select Move To
to change its order in the policy list.
Type a number in the Move to field to specify where in the policy list to move the policy and select OK.
Select Delete
to remove a policy from the list.
Enabling and disabling policies
You can enable and disable policies in the policy list to control whether the policy is active or not. The
DFL-1000 NPG matches enabled policies but does not match disabled policies.
Disabling a policy
Disable a policy to temporarily prevent the firewall from selecting the policy.
Go to Firewall > Policy .
Select the tab for the policy list containing the policy to disable.
Clear the check box of the policy to disable.
Enabling a policy
Enable a policy that has been disabled so that the firewall can match connections with the policy.
Go to Firewall > Policy .
Select the tab for the policy list containing the policy to enable.
Select the check box of the policy to enable.
Addresses
All policies require source and destination addresses. To add an address to a policy between two
interfaces, you must first add addresses to the address list for each interface. These addresses must be
valid addresses for the network connected to that interface.
By default, the firewall includes two addresses that cannot be edited or deleted:

Содержание

Скачать