D-Link DFL-1000 [55/168] Example policies

D-Link DFL-1000 [55/168] Example policies
DFL-1000 User Manual
5
5
Example policies
NAT policy for public access to a server
Routing policy for access to a server from the internal network
Transparent mode policy for public access to a server
Denying connections from the Internet
Denying connections to the Internet
Adding policies that accept connections
Requiring authentication to connect to the Internet
NAT policy for public access to a server
The following example NAT policy, to accept connections from the Internet and forward them to the DMZ
network, is similar to any NAT policy for connections between a less secure network and a more secure
network.
To add a NAT Ext -> DMZ policy:
Add a Virtual IP that maps the public IP address of the server to the actual address of the server.
See Virtual IPs
.
Go to
Firewall > Policy > Ext
->
DMZ
.
Select New to add a new policy.
Configure the policy.
Source
External_All.
Destination
The Virtual IP added in Step 1.
Schedule
Always.
Service
Select a service to match the Internet server.
For a web server, select HTTP.
Action
ACCEPT.
NAT
Select NAT.
Authentication
Select Authentication and select a user group if you want users on the Internet to authenticate with
the firewall before accessing the server.
Web filter
Select Web filter if service is set to HTTP, SMTP, POP3, or IMAP to apply content filtering to the
network traffic allowed by this policy.
Select OK to save the policy.
Arrange the policy in the policy list to produce the results that you expect.
Arranging policies in a policy list is described in Configuring policy lists
.
Routing policy for access to a server from the internal
network
The following example routing policy, to accept connections from the internal network and forward them
to the DMZ network, is similar to any routing policy. In this example, the DFL-1000 NPG is running in

Содержание

Скачать