Administrator's Guide - Kerio Software Archive

Administrator's Guide - Kerio Software Archive Administrator's Guide - Kerio Software Archive

download.kerio.com
from download.kerio.com More from this publisher
30.01.2015 Views

Traffic Policy Note: Connection cannot be logged for blocking and dropping rules (connection is not even established). The following columns are hidden in the default settings of the Traffic Policy window (for details on showing and hiding columns, see chapter 3.3): Valid on Time interval within which the rule will be valid. Apart from this interval Kerio Control ignores the rule. The special always option can be used to disable the time limitation (it is not displayed in the Traffic Policy dialog). When a denying rule is applied and/or when an allowing rule’s appliance terminates, all active network connections matching the particular rule are closed immediately. Protocol inspector Selection of a protocol inspector that will be applied on all traffic meeting the rule. The menu provides the following options to select from: Figure 7.20 Traffic rule — protocol inspector selection • Default — all necessary protocol inspectors (or inspectors of the services listed in the Service entry) will be applied on traffic meeting this rule. • None — no inspector will be applied (regardless of how services used in the Service item are defined). • Other — selection of a particular inspector which will be applied to traffic meeting this rule (all Kerio Control’s protocol inspectors are available). No other protocol inspector will be applied to the traffic, regardless of settings of services in the Service section. 96

7.4 Basic Traffic Rule Types Do not use this option unless the appropriate traffic rule defines a protocol belonging to the inspector. Functionality of the service might be affected by using an inappropriate inspector. For more information, refer to chapter 7.7. Note: Use the Default option for the Protocol Inspector item if a particular service (see the Service item) is used in the rule definition (the protocol inspector is included in the service definition). 7.4 Basic Traffic Rule Types Kerio Control traffic policy provides a range of network traffic filtering options. In this chapter you will find some rules used to manage standard configurations. Using these examples you can easily create a set of rules for your network configuration. IP Translation (NAT) IP translation (as well as Internet connection sharing) is a term used for the exchange of a private IP address in a packet going out from the local network to the Internet with the IP address of the Internet interface of the Kerio Control host. This technology is used to connect local private networks to the Internet by a single public IP address. The following example shows an appropriate traffic rule: Figure 7.21 A typical traffic rule for NAT (Internet connection sharing) Source The Trusted / Local interfaces group. This group includes all segments of the LAN connected directly to the firewall. If access to the Internet from some segments is supposed to be blocked, the most suitable group to file the interface into is Other interfaces. If the local network consists of cascaded segments (i.e. it includes other routers), it is not necessary to customize the rule in accordance with this fact — it is just necessary to set routing correctly (see chapter 18.1). Destination The Internet interfaces group. With this group, the rule is usable for any type of Internet connection (see chapter 6) and it is not necessary to modify it even it Internet connection is changed. 97

7.4 Basic Traffic Rule Types<br />

Do not use this option unless the appropriate traffic rule defines a protocol belonging<br />

to the inspector. Functionality of the service might be affected by using an<br />

inappropriate inspector.<br />

For more information, refer to chapter 7.7.<br />

Note: Use the Default option for the Protocol Inspector item if a particular service (see the<br />

Service item) is used in the rule definition (the protocol inspector is included in the service<br />

definition).<br />

7.4 Basic Traffic Rule Types<br />

<strong>Kerio</strong> Control traffic policy provides a range of network traffic filtering options. In this chapter<br />

you will find some rules used to manage standard configurations. Using these examples you<br />

can easily create a set of rules for your network configuration.<br />

IP Translation (NAT)<br />

IP translation (as well as Internet connection sharing) is a term used for the exchange of a<br />

private IP address in a packet going out from the local network to the Internet with the IP<br />

address of the Internet interface of the <strong>Kerio</strong> Control host. This technology is used to connect<br />

local private networks to the Internet by a single public IP address.<br />

The following example shows an appropriate traffic rule:<br />

Figure 7.21<br />

A typical traffic rule for NAT (Internet connection sharing)<br />

Source<br />

The Trusted / Local interfaces group. This group includes all segments of the LAN<br />

connected directly to the firewall. If access to the Internet from some segments is<br />

supposed to be blocked, the most suitable group to file the interface into is Other interfaces.<br />

If the local network consists of cascaded segments (i.e. it includes other routers), it is not<br />

necessary to customize the rule in accordance with this fact — it is just necessary to set<br />

routing correctly (see chapter 18.1).<br />

Destination<br />

The Internet interfaces group. With this group, the rule is usable for any type of Internet<br />

connection (see chapter 6) and it is not necessary to modify it even it Internet connection<br />

is changed.<br />

97

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!