Cisco PIX 525 Dokumentacja Strona 438

  • Pobierz
  • Dodaj do moich podręczników
  • Drukuj
Przeglądanie stron 437
25-24
Cisco Security Appliance Command Line Configuration Guide
OL-6721-01
Chapter 25 Configuring Tunnel Groups, Group Policies, and Users
Group Policies
Enter the following commands to set the appropriate client firewall parameters. Table 25-1, following
this set of commands, explains the syntax elements of these commands:
hostname(config-group-policy)# client-firewall none
hostname(config-group-policy)# client-firewall opt | req custom vendor-id
num
product-id
num
policy AYT | {CPP acl-in
ACL
acl-out
ACL
} [description
string
]
hostname(config-group-policy)# client-firewall opt | req zonelabs-zonealarm policy AYT |
{CPP acl-in
ACL
acl-out
ACL
}
hostname(config-group-policy)# client-firewall opt | req zonelabs-zonealarmorpro policy
AYT | {CPP acl-in
ACL
acl-out
ACL
}
client-firewall opt | req zonelabs-zonealarmpro policy AYT | {CPP acl-in
ACL
acl-out
ACL
}
hostname(config-group-policy)# client-firewall opt | req cisco-integrated acl-in
ACL
acl-out
ACL
hostname(config-group-policy)# client-firewall opt | req sygate-personal
hostname(config-group-policy)# client-firewall opt | req sygate-personal-pro
hostname(config-group-policy)# client-firewall opt | req sygate-security-agent
hostname(config-group-policy)# client-firewall opt | req networkice-blackice
hostname(config-group-policy)# client-firewall opt | req cisco-security-agent
Table 25-1 client-firewall Command Parameters
Parameter Description
acl-in <ACL> Provides the policy the client uses for inbound traffic.
acl-out <ACL> Provides the policy the client uses for outbound traffic.
AYT Specifies that the client PC firewall application controls the firewall
policy. The security appliance checks to make sure that the firewall
is running. It asks, “Are You There?” If there is no response, the
security appliance tears down the tunnel.
cisco-integrated Specifies Cisco Integrated firewall type.
cisco-security-agent Specifies Cisco Intrusion Prevention Security Agent firewall type.
CPP Specifies Policy Pushed as source of the VPN client firewall policy.
custom Specifies Custom firewall type.
description <string> Describes the firewall.
networkice-blackice Specifies Network ICE Black ICE firewall type.
none Indicates that there is no client firewall policy. Sets a firewall policy
with a null value, thereby disallowing a firewall policy. Prevents
inheriting a firewall policy from a default or specified group policy.
opt Indicates an optional firewall type.
product-id Identifies the firewall product.
req Indicates a required firewall type.
sygate-personal Specifies Sygate Personal firewall type.
sygate-personal-pro Specifies Sygate Personal Pro firewall type.
Przeglądanie stron 437
1 2 ... 433 434 435 436 437 438 439 440 441 442 443 ... 603 604

Komentarze do niniejszej Instrukcji

Brak uwag