WatchGuard Firebox System 7.0 User Guide

WatchGuard Firebox System 7.0 User Guide WatchGuard Firebox System 7.0 User Guide

watchguard.com
from watchguard.com More from this publisher
11.07.2015 Views

Chapter 8: Configuring Filtered ServicesCustom programRuns a program when the event occurs. Enter thepath of the executable file in the box provided, orbrowse to specify a path.Launch interval and repeat count work in conjunction tocontrol notification timing. For more information on thissetting, see “Setting Launch Interval and Repeat Count” onpage 217.Service PrecedencePrecedence is generally given to the most specific serviceand descends to the most general service. However, exceptionsexist. There are three different precedence groups forservices:• The “Any” service (see the Reference Guide for moreinformation about the “Any” filtered service). Thisgroup has the highest precedence.• IP and ICMP services and all TCP/UDP services thathave a port number specified. This group has thesecond highest precedence and is the largest of thethree.• “Outgoing” services that do not specify a port number(they apply to any port). This group includes OutgoingTCP, Outgoing UDP, and Proxy.“Multiservices” can contain subservices of more than oneprecedence group. “Filtered-HTTP” and “Proxied-HTTP,”for example, contain both a port-specific TCP subservicefor port 80 as well as a nonport subservice that covers allother TCP connections. When precedence is being determined,individual subservices are given precedenceaccording to their group (described previously) independentof the other subservices contained in the multiservice.Precedence is determined by group first. As shown in thefollowing diagram, services from a higher precedence130 WatchGuard Firebox System

Service Precedencegroup always have higher precedence than the services ofa lower precedence group, regardless of their individualsettings. For example, because the “Any” service is in thehighest precedence group, all incidences of the “Any” servicewill take precedence over the highest precedence Telnetservice.The precedences of services that are in the same precedencegroup are ordered from the most specific services(based on source and destination targets) to the least specificservice. The method used to sort services is based onthe specificity of targets, from most specific to least specific.User Guide 131

Service Precedencegroup always have higher precedence than the services ofa lower precedence group, regardless of their individualsettings. For example, because the “Any” service is in thehighest precedence group, all incidences of the “Any” servicewill take precedence over the highest precedence Telnetservice.The precedences of services that are in the same precedencegroup are ordered from the most specific services(based on source and destination targets) to the least specificservice. The method used to sort services is based onthe specificity of targets, from most specific to least specific.<strong>User</strong> <strong>Guide</strong> 131

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!