WSM User Guide - WatchGuard Technologies

WSM User Guide - WatchGuard Technologies WSM User Guide - WatchGuard Technologies

watchguard.com
from watchguard.com More from this publisher
12.07.2015 Views

Configuring Policy PropertiesSetting advanced propertiesYou use the Advanced tab of the Edit Policy Properties dialog box to set a policy schedule, implementQuality of Service (QoS) settings, apply NAT rules, configure ICMP error handling for this policy, and set acustom idle time-out.Setting a scheduleYou can set an operating schedule for the policy. You can use the schedule templates in the Scheduledrop-down list or create a custom schedule. For information, see the “Basic Configuration Setup” chapterin this guide.Note that schedules can be shared by more than one policy.Applying a Quality of Service (QoS) actionIf you have Fireware® Pro on your Firebox, you can assign a Quality of Service action to the policy. Usethe button on the far right to create a new QoS action. After you create a new QoS action, it appears inthe QoS drop-down list. For more information, see “Creating QoS Actions” on page 323.Note that these actions can be shared by more than one policy.Applying NAT rulesYou can apply Network Address Translation (NAT) rules to a policy:1-to-1 NATWith this type of NAT, the Firebox uses private and public IP ranges that you set, as described in“Using 1-to-1 NAT” on page 116.Dynamic NATWith this type of NAT, the Firebox maps private IP addresses to public IP addresses. Select UseNetwork NAT Settings if you want to use the dynamic NAT rules set for the Firebox. Select Alltraffic in this policy if you want to apply NAT to all traffic in this policy.You also have the option to set a dynamic NAT source IP address for any policy that uses156 WatchGuard System Manager

Setting Policy Precedencedynamic NAT. This makes sure that any traffic that uses this policy shows a specified addressfrom your public or external IP address range as the source. You would most often do this toforce outgoing SMTP traffic to show your domain’s MX record address when the IP address onthe Firebox’s external interface is not the same as your MX record IP address.1-to-1 NAT rules have higher precedence than dynamic NAT rulesNoteIf you use multi-WAN, you cannot use the Set Source IP option. Use this option only when your Fireboxuses a single external interface.Setting ICMP error handlingYou can set the ICMP error handling settings associated with the policy.From the drop-down list, select:Use global settingUse the global ICMP error handling setting set for the Firebox. For information on this globalsetting, see “ICMP error handling” on page 76.Specify settingConfigure a parameter that overrides the global setting. Click ICMP Setting. From the ICMPError Handling Settings dialog box, select the check boxes to configure individual settings. Forinformation on these settings, see “ICMP error handling” on page 76.Setting a custom idle time-outTo set an idle time-out, click Specify Custom Idle Timeout and click the arrows to set the number ofseconds before time-out. This setting overrides the idle time-out of the policy.Setting Policy PrecedencePrecedence is the sequence in which the Firebox® examines network traffic and applies a policy rule. TheFirebox routes the traffic that uses the rules for the first policy that the traffic matches. Fireware® PolicyManager automatically sorts policies from the most detailed to the most general. You can also manuallyset the precedence.Using automatic orderFireware Policy Manager automatically sorts policies from the most detailed to the most general. Eachtime you add a policy, Policy Manager compares the new rule with all the rules in your configuration file.To set the precedence, Policy Manager uses these criteria:1 Protocols set for the policy typeUser Guide 157

Configuring Policy PropertiesSetting advanced propertiesYou use the Advanced tab of the Edit Policy Properties dialog box to set a policy schedule, implementQuality of Service (QoS) settings, apply NAT rules, configure ICMP error handling for this policy, and set acustom idle time-out.Setting a scheduleYou can set an operating schedule for the policy. You can use the schedule templates in the Scheduledrop-down list or create a custom schedule. For information, see the “Basic Configuration Setup” chapterin this guide.Note that schedules can be shared by more than one policy.Applying a Quality of Service (QoS) actionIf you have Fireware® Pro on your Firebox, you can assign a Quality of Service action to the policy. Usethe button on the far right to create a new QoS action. After you create a new QoS action, it appears inthe QoS drop-down list. For more information, see “Creating QoS Actions” on page 323.Note that these actions can be shared by more than one policy.Applying NAT rulesYou can apply Network Address Translation (NAT) rules to a policy:1-to-1 NATWith this type of NAT, the Firebox uses private and public IP ranges that you set, as described in“Using 1-to-1 NAT” on page 116.Dynamic NATWith this type of NAT, the Firebox maps private IP addresses to public IP addresses. Select UseNetwork NAT Settings if you want to use the dynamic NAT rules set for the Firebox. Select Alltraffic in this policy if you want to apply NAT to all traffic in this policy.You also have the option to set a dynamic NAT source IP address for any policy that uses156 <strong>WatchGuard</strong> System Manager

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!