12.07.2015 Views

WSM User Guide - WatchGuard Technologies

WSM User Guide - WatchGuard Technologies

WSM User Guide - WatchGuard Technologies

SHOW MORE
SHOW LESS

Create successful ePaper yourself

Turn your PDF publications into a flip-book with our unique Google optimized e-Paper software.

Packet Filter PoliciesAOLThe America Online proprietary protocol allows access to AOL through a TCP/IP network. The AOL clientmust be specially configured to use TCP/IP and not a modem.Characteristics• Internet Protocol(s): TCP• Port Number(s): 5190archiearchie is a search protocol used to find files on FTP servers. We recommend that you use the availableweb interfaces to archie. A current list of archie servers is available through anonymous FTP from:ftp://microlib.cc.utexas.edu/microlib/mac/info/archie-servers.txtExternal hosts can be spoofed. The Firebox cannot make sure that these packets were sent from the correctlocation. You can configure your Firebox to add the source IP address to the Blocked Sites list whenan incoming archie connection is denied. You can use all of the usual log options with archie.Characteristics• Internet Protocol(s): UDP• Port Number(s): 1525authThe Authentication Server protocol (AUTH) has a new name. It is now called the Identification Protocol(IDENT). Refer to IDENT for more information about this policy.BGPBorder Gateway Protocol (BGP) is the routing protocol used across most of the Internet. It is a highlyconfigurable protocol that can add redundancy to links to and from the Internet for LANs. We recommendthat you use this service only if you have enabled and configured BGP in the dynamic routing processesin the Fireware® configuration.Characteristics• Internet Protocol(s): TCP or UDP• Port Number(s): 179CitrixCitrix, or Independent Computing Architecture (ICA), is an application protocol used by Citrix softwareapplications such as Winframe and Metaframe Presentation Server (MPS). Winframe gives access to aWindows computer from different types of clients that use TCP port 1494. Citrix MPS 3.0 uses ICA withSession Reliability over TCP port 2598. If you use Citrix MPS, you must add a custom policy for TCP port2598. If you add the Citrix policy, you could put your network security at risk because it allows remoteaccess to computers through the firewall without authentication. The threat to a Winframe or MPS380 <strong>WatchGuard</strong> System Manager

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!