30.01.2015 Views

Administrator's Guide - Kerio Software Archive

Administrator's Guide - Kerio Software Archive

Administrator's Guide - Kerio Software Archive

SHOW MORE
SHOW LESS

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

7.3 Definition of Custom Traffic Rules<br />

• No Translation — destination address will not be modified.<br />

• Translate to — IP address that will substitute the packet’s destination address. This<br />

address also represents the IP address of the host on which the service is actually<br />

running.<br />

The Translate to entry can be also specified by DNS name of the destination computer.<br />

In such cases <strong>Kerio</strong> Control finds a corresponding IP address using a DNS query.<br />

Warning:<br />

We recommend you not to use names of computers which are not<br />

recorded in the local DNS since rule is not applied until a corresponding<br />

IP address is found. This might cause temporary malfunction of the<br />

mapped service.<br />

• Translate port to — during the process of IP translation you can also substitute the<br />

port of the appropriate service. This means that the service can run at a port that is<br />

different from the port where it is available from the Internet.<br />

Note: This option cannot be used unless only one service is defined in the Service entry<br />

within the appropriate traffic rule and this service uses only one port or port range.<br />

For examples of traffic rules for port mapping and their settings, refer to chapter 7.4.<br />

Log<br />

The following actions can be taken to log traffic:<br />

Figure 7.19<br />

Traffic rule — packet/connection logging<br />

• Log matching packets — all packets matching with rule (permitted, denied or dropped,<br />

according to the rule definition) will be logged in the Filter log.<br />

• Log matching connections — all connections matching this rule will be logged in<br />

the Connection log (only for permit rules). Individual packets included in these<br />

connections will not be logged.<br />

95

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!