Download Gauntlet® for IRIX® Netperm Table Reference Guide Version 4.1

Transcript
Chapter 3: Policies and Services
Denying Access to a Host, Network, or Proxy
You can deny access to a particular host or network on a proxy or general basis.
Denying Access by Proxy
To deny access by proxy, add a deny-destination line to the specific proxy.
For example, Yoyodyne does not want anyone on the inside networks to transfer files
using FTP from any hosts at Big University:
55 ftp-gw: deny-destination *.bigu.edu
Denying General Access to a Host or Network
You can also deny access to a particular host or network for all proxies and applications.
To deny access for all applications, add a deny-destination line to the appropriate policy.
For example, Yoyodyne does not want anyone on the inside network to communicate
with Big University:
108 policy-trusted: deny-destination *.bigu.edu
Note that the SMAP proxies do not use the policy rules, so you can still send mail to the
denied host or network.
Controlling Services by User, Group, or Time
You can control access to the following proxies on a per user, per group, or time of day
basis:
16
ck-gw
Circuit proxy
ftp-gw
FTP proxy
rlogin-gw
Rlogin proxy
rsh-gw
Rsh proxy
tn-gw
TELNET proxy