Access Control Objects provide an hierarchical override mechanism. Objects on cluster level sharing the same name as global or range objects override the global definition(s). This mechanism works like the one using global firewall objects for the Barracuda NG Firewall.

2.4Access Control Service Trustzone

Each Access Control Service belongs to a so-called trustzone. To enable a company to enforce their security policies across multiple Barracuda NG Firewalls the Barracuda NG Control Center provides Access Control Service Trustzones as global objects. This advanced feature allows all Access Control Services within the same trust zone to share the same set of security policies. In addition they share a signing key, so that a mutual trust relationship can be established.

On stand-alone Barracuda NG Firewalls, configuration of the trustzone is located in the configuration node Virtual Servers > <servername> > Assigned Services > <servicename> (Access Control

Service) > Access Control Service Trustzones.

The Barracuda NG Control Center provides Access Control Service Trustzones either within the Global Settings directory or specifically as Range Settings or Cluster Settings. As usual these objects permit access only to administrators with appropriate administrative scope and appropriate permission.

Fig. 2–7Access Control Service Trustzone - Configuration tree

25 Barracuda NG Network Access Client - Administrator’s Guide

Page 27
Image 27
Barracuda Networks VERSION SP4 manual 7Access Control Service Trustzone Configuration tree