Download 602LAN SUITE 2004 Manual
Transcript
DESTINATION_IP AND DESTINATION _MASK = WHERE_IP AND DESTINATION _MASK The connection will be established if the result of both logic operations is true and the rule is green. The IP filter rules are checked from top to bottom. From the red/green (disabled/enabled) rule you have two choices: • • Only grant several users Internet access. Only restrict several users from Internet access. If you need to move a rule level up or down, highlight it and push Crtl + Up arrow / Crtl + Down arrow. If you want to delete any item from the list, highlight the item and press the Delete button. You can also edit the highlighted items. Their values move into the edit fields. NOTE: If using a Parent proxy/cache server it is not possible to restrict communication using the IP mask because the Proxy Server in this case does not verify the IP address of the destination computer. For access restriction to some computers use the Site Access tab. IP Filter Settings – Example 1 You need for your company the following IP filter settings: • • • Restrict three employees with following IP addresses – 192.168.1.25, 192.168.1.35, 192.168.1.38 Allow all others Internet access Outside users from the Internet need to have access to only one computer with the 192.168.1.1 IP address. Solution: • • • The first three rules deny the three computers 192.168.1.25, 192.168.1.35, 192.168.1.38 access to any computer through the firewall (i.e. this restricts these three employees access the Internet). The fourth rule grants all users of the 192.168.1.0 network communication with any computer through firewall (i.e. it allows all users including 192.168.1.25, 192.168.1.35, and 192.168.1.38 users access to the Internet). But, since the IP filter rules are checked from top to the bottom, users 192.168.1.25, 192.168.1.35, 192.168.1.38 do not have access to the Internet. The fifth rule grants any communication with 192.168.1.1 through the firewall (i.e. this rule allows ANY Internet users access to the 192.168.1.1 computer). NOTE: If the fourth rule were in the first position, it would not be able to restrict those 192.168.1.25, 192.168.1.35, 192.168.1.38 users. © 2004 Software602, Inc. 9/2004 66