D-Link DFL-1000 [58/168] Adding policies that accept connections

D-Link DFL-1000 [58/168] Adding policies that accept connections
DFL-1000 User Manual
5
8
from addresses on the internal network,
to addresses on the Internet,
to specific services,
according to one-time or recurring schedules.
The following example procedure, to prevent all users on the internal network from using POP3 to
connect to an email server on the Internet, is similar to any procedure to deny a connection that would
otherwise be accepted by the default policy. In this example, the DFL-1000 NPG is running in NAT/Route
mode.
To deny a connection to the Internet:
Go to Firewall > Policy > Int -> Ext .
If it has not been removed, the default policy should be in this policy list.
Select Insert Policy before
to add a new policy above the default policy.
You must add the deny policy above the default policy in the policy list so that the deny policy is matched
before the default policy. For more information on arranging policies in policy lists, see Policy matching in
detail and Configuring policy lists.
Configure the policy to match the default policy, with the following exceptions:
Set Service to POP3.
Set Action to DENY.
Select OK to save the policy.
The policy is added to the policy list above the default policy.
Adding policies that accept connections
Policies that accept connections can be used:
as exceptions to policies that deny connections,
For example, if a policy denies connections from a subnet, you can add a policy that accepts
connections from one of the computers on the subnet. Such policies must be added to the policy list
above the connections that they are exceptions to.
as a replacement for the default policy to accept only the connections that you want the firewall to
accept.
You can limit access to the Internet to that allowed in the policies that you create. You must delete the
default policy. If the default policy remains in the policy list, all connections that do not match a policy
will be accepted by the default policy.
The following example procedure, to accept connections from the internal network to the Internet, is
similar to any procedure to accept connections. In this example, the DFL-1000 NPG is running in
NAT/Route mode.
To accept a connection to the Internet:
Add addresses, services, or schedules as required.
Go to Firewall > Policy > Int
->
Ext .
Select New to add a policy.
You can also select Insert Policy before
on a policy in the list to add the new policy above a
specific policy. You would do this if you were adding an accept policy as an exception to a deny policy.
Configure the policy to match the type of connection to accept and set Action to ACCEPT.
Select OK to save the policy.

Содержание

Скачать