12.07.2015 Views

WSM User Guide - WatchGuard Technologies

WSM User Guide - WatchGuard Technologies

WSM User Guide - WatchGuard Technologies

SHOW MORE
SHOW LESS

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

Packet Filter PoliciesCharacteristics• Internet Protocol(s): TCP and UDP• Port Number(s): TCP 111, UDP 111syslogsyslog is a policy used to record operating system events on UNIX hosts. Syslog data is usually enabledon a firewall to collect data from a host outside the firewall.The syslog port is blocked in the default Firebox configuration. To allow one log host to collect logs frommore than one Firebox:• Remove port 514 from the Blocked Ports list• Add the <strong>WatchGuard</strong> Logging policy to Policy ManagerNoteIt is usually not secure to allow syslog traffic through the Firebox. It is possible for hackers to fill syslogswith log entries. If the syslog is full, it is more difficult to see an attack. Also, the disk frequently fills upand the attack is not recorded.Characteristics• Internet Protocol(s): UDP• Port Number(s): 514TACACSTACACS user authentication is a system that uses user accounts to authenticate users into a dial-upmodem pool. This removes the need to keep copies of accounts on a UNIX system. TACACS does notsupport TACACS+ or RADIUS.Characteristics• Internet Protocol(s): UDP• Port Number(s): 49TACACS+TACACS+ user authentication is a system that uses user accounts to authenticate users into a dial-upmodem pool. This eliminates the need to keep copies of accounts on a UNIX system. TACACS+ supportsRADIUS.Characteristics• Internet Protocol(s): TCP• Port Number(s): 49TCPThis policy serves as the default policy for all TCP connections, and other policies override it. TCP connectionsthat do not match specified policies in Policy Manager do not complete unless TCP-UDP, TCP, or394 <strong>WatchGuard</strong> System Manager

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!