ProSecure Unified Threat Management (UTM) Appliance

The following section summarizes the various criteria that you can apply to outbound rules in order to reduce traffic. For more information about outbound rules, see Outbound Rules (Service Blocking) on page 129. For detailed procedures on how to configure outbound rules, see Configure LAN WAN Rules on page 139 and Configure DMZ WAN Rules on page 142.

When you define outbound firewall rules, you can further refine their application according to the following criteria:

Services. You can specify the services or applications, or groups of services or applications to be covered by an outbound rule. If the desired service or application does not display in the list, you need to define it using the Services screen (see Outbound Rules (Service Blocking) on page 129 and Add Customized Services on page 163).

LAN users (or DMZ users). You can specify which computers on your network are affected by an outbound rule. There are several options:

-Any. The rule applies to all computers and devices on your LAN or DMZ

-Single address. The rule applies to the address of a particular computer.

-Address range. The rule applies to a range of addresses.

-Groups. The rule applies to a group of computers. (You can configure groups for LAN WAN outbound rules but not for DMZ WAN outbound rules.) The Known PCs and Devices table is an automatically maintained list of all known computers and network devices and is generally referred to as the network database, which is described in Manage the Network Database on page 112. Computers and network devices are entered into the network database by various methods, which are described in Manage Groups and Hosts (LAN Groups) on page 111.

-IP Groups. The rule applies to a group of individual LAN IP addresses. Use the IP Groups screen (under the Network Security main navigation menu) to assign IP addresses to groups. For more information, see Create IP Groups on page 167. (You cannot configure IP groups for DMZ WAN outbound rules.)

WAN users. You can specify which Internet locations are covered by an outbound rule, based on their IP address:

-Any. The rule applies to all Internet IP address.

-Single address. The rule applies to a single Internet IP address.

-Address range. The rule applies to a range of Internet IP addresses.

-IP Groups. The rule applies to a group of individual WAN IP addresses. Use the IP Groups screen (under the Network Security main navigation menu) to assign IP addresses to groups. For more information, see Create IP Groups on page 167.

Users allowed. You can specify that the rule applies to individual users in the network, groups in the network, or both. To configure users accounts, see Configure User Accounts on page 401. To configure groups, see Configure Groups on page 394 and Configure Custom Groups on page 397.

Schedule. You can configure multiple schedules to specify when a rule is applied. Once a schedule is configured, it affects all rules that use this schedule. You specify the days of the week and time of day for each schedule. For more information, see Set a Schedule to Block or Allow Specific Traffic on page 177.

Network and System Management

430

Page 430
Image 430
NETGEAR UTM5EW-100NAS, STM150EW-100NAS manual 430