Symantec 360R Administration Guide - Page 77

Disabling NAT mode, Enabling IPsec pass-thru, Firewall, Enable IDENT Port

Page 77 highlights

Network traffic control 77 Configuring advanced options To enable the IDENT Port See "Advanced tab field descriptions" on page 186. 1 In the SGMI, in the left pane, click Firewall. 2 In the right pane, on the Advanced tab, under Optional Security Settings, check Enable IDENT Port. 3 Click Save. Disabling NAT mode You can configure the security gateway to work as a standard network router to separate different subnets on an internal network. Disabling NAT Mode disables the firewall security functions. This setting should only be used for Intranet deployments where the security gateway is used as a bridge on a protected network. When the security gateway is configured for NAT mode, it behaves as a 802.1D (MAC bridge) device. To disable NAT Mode See "Advanced tab field descriptions" on page 186. 1 In the SGMI, in the left pane, click Firewall. 2 In the right pane, on the Advanced tab, under Optional Security Settings, check Disable NAT Mode. 3 Click Save. Enabling IPsec pass-thru IPsec pass-thru is supported by the security gateway. If the VPN client used in Exposed Host (DMZ) has problems connecting from behind the security gateway, use the None setting. The following list includes the supported IPsec types: ■ 1 SPI ADI - Assured Digital ■ 2 SPI Standard (Symantec, Cisco Pix, and Nortel Contivity) clients ■ 2 SPI-C Cisco Concentrator 30X0 Series clients

  • 1
  • 2
  • 3
  • 4
  • 5
  • 6
  • 7
  • 8
  • 9
  • 10
  • 11
  • 12
  • 13
  • 14
  • 15
  • 16
  • 17
  • 18
  • 19
  • 20
  • 21
  • 22
  • 23
  • 24
  • 25
  • 26
  • 27
  • 28
  • 29
  • 30
  • 31
  • 32
  • 33
  • 34
  • 35
  • 36
  • 37
  • 38
  • 39
  • 40
  • 41
  • 42
  • 43
  • 44
  • 45
  • 46
  • 47
  • 48
  • 49
  • 50
  • 51
  • 52
  • 53
  • 54
  • 55
  • 56
  • 57
  • 58
  • 59
  • 60
  • 61
  • 62
  • 63
  • 64
  • 65
  • 66
  • 67
  • 68
  • 69
  • 70
  • 71
  • 72
  • 73
  • 74
  • 75
  • 76
  • 77
  • 78
  • 79
  • 80
  • 81
  • 82
  • 83
  • 84
  • 85
  • 86
  • 87
  • 88
  • 89
  • 90
  • 91
  • 92
  • 93
  • 94
  • 95
  • 96
  • 97
  • 98
  • 99
  • 100
  • 101
  • 102
  • 103
  • 104
  • 105
  • 106
  • 107
  • 108
  • 109
  • 110
  • 111
  • 112
  • 113
  • 114
  • 115
  • 116
  • 117
  • 118
  • 119
  • 120
  • 121
  • 122
  • 123
  • 124
  • 125
  • 126
  • 127
  • 128
  • 129
  • 130
  • 131
  • 132
  • 133
  • 134
  • 135
  • 136
  • 137
  • 138
  • 139
  • 140
  • 141
  • 142
  • 143
  • 144
  • 145
  • 146
  • 147
  • 148
  • 149
  • 150
  • 151
  • 152
  • 153
  • 154
  • 155
  • 156
  • 157
  • 158
  • 159
  • 160
  • 161
  • 162
  • 163
  • 164
  • 165
  • 166
  • 167
  • 168
  • 169
  • 170
  • 171
  • 172
  • 173
  • 174
  • 175
  • 176
  • 177
  • 178
  • 179
  • 180
  • 181
  • 182
  • 183
  • 184
  • 185
  • 186
  • 187
  • 188
  • 189
  • 190
  • 191
  • 192
  • 193
  • 194
  • 195
  • 196
  • 197
  • 198
  • 199
  • 200
  • 201
  • 202
  • 203
  • 204
  • 205
  • 206
  • 207
  • 208
  • 209
  • 210
  • 211
  • 212
  • 213
  • 214
  • 215
  • 216
  • 217
  • 218

77
Network traffic control
Configuring advanced options
To enable the IDENT Port
See
“Advanced tab field descriptions”
on page 186.
1
In the SGMI, in the left pane, click
Firewall
.
2
In the right pane, on the Advanced tab, under Optional Security Settings,
check
Enable IDENT Port
.
3
Click
Save
.
Disabling NAT mode
You can configure the security gateway to work as a standard network router to
separate different subnets on an internal network. Disabling NAT Mode disables
the firewall security functions. This setting should only be used for Intranet
deployments where the security gateway is used as a bridge on a protected
network. When the security gateway is configured for NAT mode, it behaves as a
802.1D (MAC bridge) device.
To disable NAT Mode
See
“Advanced tab field descriptions”
on page 186.
1
In the SGMI, in the left pane, click
Firewall
.
2
In the right pane, on the Advanced tab, under Optional Security Settings,
check
Disable NAT Mode
.
3
Click
Save
.
Enabling IPsec pass-thru
IPsec pass-thru is supported by the security gateway. If the VPN client used in
Exposed Host (DMZ) has problems connecting from behind the security gateway,
use the None setting.
The following list includes the supported IPsec types:
1 SPI
ADI - Assured Digital
2 SPI
Standard (Symantec, Cisco Pix, and Nortel Contivity) clients
2 SPI-C
Cisco Concentrator 30X0 Series clients