WatchGuard Firebox System 7.0 User Guide

WatchGuard Firebox System 7.0 User Guide WatchGuard Firebox System 7.0 User Guide

watchguard.com
from watchguard.com More from this publisher
11.07.2015 Views

Chapter 9: Configuring Proxied ServicesFrom Policy Manager:1 If you have not done so already, use the Add Servicebutton to add the FTP proxy service. Expand theProxies tree and double-click the FTP service icon.2 Click the Properties tab. Click Settings.The Settings information appears as shown in the followingfigure.3 Enable FTP proxy properties according to yoursecurity policy preferences.For a description of each control, right-click it, and then selectWhat’s This?. You can also refer to the “Field Definitions”chapter in the Reference Guide.Note that the Make Incoming FTP Connections Read onlycheckbox is selected by default. If you have an FTP server thataccepts files, be sure to clear this checkbox.4 Click OK.Enabling protocol anomaly detection for FTPFor a description of protocol anomaly detection, see “ProtocolAnomaly Detection” on page 136.1 From the FTP Properties dialog box, click theProperties tab.2 Select the Enable auto-blocking of sites usingprotocol anomaly detection checkbox.3 To set rules for anomaly detection, click the AutoblockingRules button.The PAD Rules for FTP Proxy dialog box appears, as shown inthe following figure.150 WatchGuard Firebox System

Selecting an HTTP Service4 Select the rules to determine which packet originatorsare automatically added to the auto-blocked sites list.Selecting an HTTP ServiceBecause of the extensive security implications of HTTPtraffic, it is important to restrict the incoming service asmuch as possible. Many administrators set up public Webservers only on their optional interface. They restrictincoming HTTP traffic to the optional interface and prohibitincoming HTTP traffic from traveling from theoptional interface to the trusted interface. Outgoing trafficis generally less restrictive. For example, many companiesopen outgoing HTTP traffic from Any to Any.WatchGuard Firebox System offers three different types ofHTTP services. Choose the HTTP service that best meetsyour needs:• Proxied-HTTP is a multiservice that combinesconfiguration options for HTTP on port 80 with a rulethat allows (by default) all outgoing TCP connections.In other words, the Proxied-HTTP is not bilateralincoming and outgoing; this service controls incomingTCP traffic only on port 80, but allows outgoing TCPtraffic on all ports. The Proxied-HTTP service includesUser Guide 151

Chapter 9: Configuring Proxied ServicesFrom Policy Manager:1 If you have not done so already, use the Add Servicebutton to add the FTP proxy service. Expand theProxies tree and double-click the FTP service icon.2 Click the Properties tab. Click Settings.The Settings information appears as shown in the followingfigure.3 Enable FTP proxy properties according to yoursecurity policy preferences.For a description of each control, right-click it, and then selectWhat’s This?. You can also refer to the “Field Definitions”chapter in the Reference <strong>Guide</strong>.Note that the Make Incoming FTP Connections Read onlycheckbox is selected by default. If you have an FTP server thataccepts files, be sure to clear this checkbox.4 Click OK.Enabling protocol anomaly detection for FTPFor a description of protocol anomaly detection, see “ProtocolAnomaly Detection” on page 136.1 From the FTP Properties dialog box, click theProperties tab.2 Select the Enable auto-blocking of sites usingprotocol anomaly detection checkbox.3 To set rules for anomaly detection, click the AutoblockingRules button.The PAD Rules for FTP Proxy dialog box appears, as shown inthe following figure.150 <strong>WatchGuard</strong> <strong>Firebox</strong> <strong>System</strong>

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!