Issue 4 May 2005 163
Chapter 8: Establishing security
This chapter describes the VPNmanager security measures you can configure to establish a
secure domain. Included in this chapter is how to set up the following:
Firewall rules set up (4.2 and later)
Denial of Service (4.X)
Services
Voice Over IP controls (4.X only)
QoS policy and QoS mapping (4.31)
Packet Filtering (3.x only)

Firewall rules set up

Use the Firewall Rules feature to manage the firewall rules that the domain and the security
gateway uses. VPNmanager firewall policy management minimizes configuration complexity
and increases scalability. The firewall policy allows deployment of a secure network
infrastructure in a relatively short amount of time.
The security gateway uses a rules-based method of packet inspection, where the priority of
each rule is determined by its position in the list (highest is top priority). The first match
determines the fate of the packet: permit or deny. If no matching rule is found, the default action
is to permit the packet.
Note:
Note: For devices with VPNos 4.1 and earlier, domain level rules and fire wall te mplates
are not available. See Voice Over IPon page 175.

Levels of firewall policy management

The Firewall Rules tab is used to manage the firewall rules both at the domain level and at the
individual device level in the domain. You can view the Firewall rules and add or edit rules from
the VPNmanager Configuration Console>View>Firewall command. Firewall policy management
includes domain firewall rules, device firewall rules, and firewall templates.