13.07.2015 Views

WatchGuard Firebox System 4.6 User Guide

WatchGuard Firebox System 4.6 User Guide

WatchGuard Firebox System 4.6 User Guide

SHOW MORE
SHOW LESS

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

Configuring services for authenticationAdding outgoing service propertiesFrom Policy Manager:1 In the Services Arena, double-click the service. Click the Outgoing tab.The Properties dialog box displays the Outgoing properties tab.2 Use the Outgoing Connections Are drop list to select Enabled and Allowed.3 To define specific users and hosts on the Trusted network that can send packetsout through the service, click Add beneath the From list.The Add Address dialog box appears. For a description, see “Adding addresses to serviceproperties” on page 50.4 To define specific allowed external destinations for traffic through this service,click Add beneath the To list.5 To customize logging and notification for outgoing traffic for this service, clickLogging. Configure logging and notification according to your security policypreferences.For a description, see “Customizing logging and notification by service or option” on page 76.6 Click OK.Adding addresses to service propertiesBoth the Incoming and Outgoing properties include From and To lists of addresses.Use the Add Address dialog box to add a network, IP address, or specific user to theFrom or To list. From the service’s Properties dialog box:1 Click Add.2 To add a member that has already been defined, click your selection on theMembers list. Click Add.The member appears in the Selected Members and Addresses list.3 To add a new entry, click Add Other.4 Use the Choose Type drop list to select the member type.5 In the Value text box, enter the member IP address or name.6 Click OK.The member appears in the Selected Members and Addresses list.7 To view a list of users associated with a host on the Members list, select themember and then click Show <strong>User</strong>s.Working with wg_ iconsService icons beginning with “wg_” are created automatically when you enablefeatures such as PPTP and authentication. These icons appear only in the Advancedview of Policy Manager, in the Services Arena. The “wg_” service icons rarely requiremodification. <strong>WatchGuard</strong> recommends leaving “wg_” icons in their default settings.Configuring services for authenticationOne way to create effective user authentication environments is to restrict alloutgoing services to allow connections only from authenticated users.50

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!