12.07.2015 Views

WSM User Guide - WatchGuard Technologies

WSM User Guide - WatchGuard Technologies

WSM User Guide - WatchGuard Technologies

SHOW MORE
SHOW LESS

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

Packet Filter PoliciesCharacteristics• Internet Protocol(s): GRE• Protocol Number(s): 47HTTPA HTTP packet filter will not apply the HTTP proxy rule set to any traffic. To proxy HTTP traffic, use theHTTP proxy policy. We recommend that incoming HTTP be allowed only to public HTTP servers locatedbehind the Firebox.External hosts can be spoofed. <strong>WatchGuard</strong> cannot verify that these packets were actually sent from thecorrect location. You can configure the Firebox to add the source IP address to the Blocked Sites listwhenever an incoming HTTP connection is denied. All of the usual log options can be used with HTTP.Characteristics• Internet Protocol(s): TCP• Port Number(s): 80HTTPSHTTPS is a secure and encrypted version of the HTTP protocol. The client and the web server set up anencrypted session on TCP port 443. Because this session is encrypted, the proxy cannot examine packetcontents using a proxy. This policy uses a packet filter to examine the connection.Characteristics• Internet Protocol(s): TCP• Port Number(s): 443HBCIThe Home Banking Computer Interface (HBCI) is a standard created for bank customers and manufacturersof banking products.Characteristics• Internet Protocol(s): TCP• Port Number(s): 3000IDENTThe Identification Protocol (IDENT) is a protocol used to match TCP connections to a user name. It isused most frequently by large public SMTP and FTP servers. It is used for logs, but you cannot trust theinformation it gives, as attackers can change their servers to have them send back incorrect information.IDENT uses “fake” information to hide internal user information.When you use SMTP with incoming static NAT, you must add IDENT to your Policy Manager. ConfigureIDENT to allow traffic to the Firebox. This enables mail messages to flow from behind the Firebox to themany SMTP servers on the Internet that use IDENT to identify other mail servers’ identities, and allowsthese servers to return messages through the Firebox to their senders.384 <strong>WatchGuard</strong> System Manager

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!