13.07.2015 Views

WatchGuard Firebox System 4.6 User Guide

WatchGuard Firebox System 4.6 User Guide

WatchGuard Firebox System 4.6 User Guide

SHOW MORE
SHOW LESS

Create successful ePaper yourself

Turn your PDF publications into a flip-book with our unique Google optimized e-Paper software.

Setting up proxy services4 Click File => Save => To <strong>Firebox</strong> to save your changes to the <strong>Firebox</strong>. Specify thelocation and name of the new configuration file.Setting up proxy servicesThe <strong>WatchGuard</strong> <strong>Firebox</strong> <strong>System</strong> uses a technology called “transparent proxies.”Transparent proxies can be employed without any special third-party or proxy-awaresoftware, and are transparent to client programs. <strong>WatchGuard</strong> has applicationspecificproxies for SMTP, FTP, and HTTP.When performing incoming, static NAT, internal hosts must point to theinternal IP address of the server, not the <strong>Firebox</strong> or public IP address.<strong>User</strong>s should have their WINS, host file, or internal DNS set to resolve tothe internal IP of the server in question. For more information, see“Configuring a service for incoming static NAT” on page 66.Configuring an SMTP proxy serviceThe SMTP proxy limits several potentially harmful aspects of e-mail. The proxy scansthe content type and content disposition headers and matches them against a userdefinablelist of known hostile signatures. E-mail containing suspect attachments isblocked and replaced with messages indicating that this action has been taken.The list of disallowed signatures can be modified from the Content Types tab in theSMTP Proxy dialog box. You do not have to reboot the <strong>Firebox</strong> when you make theseSMTP configuration changes.The proxy also automatically disables nonstandard commands such as Debug, andcan limit message size and number of recipients. If the message exceeds preset limits,the <strong>Firebox</strong> refuses the mail.The Policy Manager uses separate dialog boxes for incoming and outgoing SMTPrules. Because incoming messages pose a greater threat to your network thanoutgoing ones, the dialog box for incoming SMTP has more controls and configurableproperties.Configuring the incoming SMTP proxyUse the Incoming SMTP Proxy dialog box to set the incoming parameters of theSMTP proxy. You must already have an SMTP Proxy service icon in the ServicesArena. From the Services Arena:1 Double-click the SMTP Proxy icon to open the SMTP Proxy Properties dialog box.2 Click the Properties tab.3 Click Incoming.The Incoming SMTP Proxy dialog box appears, displaying the General tab.4 Modify general properties according to your preference.For a description of each control, right-click it, and then click What’s This?.5 To modify logging properties, click the Logging tab.52

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!