Symantec 16-00-00091 Installation Guide - Page 62

Exposed Host (DMZ), Advanced Configuration, Enable, Update Entery, Delete, Update, Clear Form

Page 62 highlights

Advanced Configuration 2. Check or uncheck the Enable box to enable or disable your server. Remember to click Update Entery if using with an existing virtual server. 3. Enter your server LAN IP. Virtual Servers need a local host with a static IP address to operate effectively. Setup a static local IP for your server using the Host IP & Group screen (or on the server itself). Enter that IP here. 4. Choose either TCP or UDP as the server protocol type. 5. In the Port Ranges fields, enter the Start and Finish ports used by your server for both Internal and External. If only one port is used, enter the same number in both Start and Finish fields. Usually Internal and External should be the same, but you can Translate ports if different values are entered (for example: 2000-2500 internally can be translated to 3000-3500 externally). 6. Click Add to add a new entry or one of the following: Click Delete to delete the entry shown and free up Symantec Firewall/VPN memory. Click Update if you have changed the entry shown. Click Clear Form before adding a new entry. Exposed Host (DMZ) This screen will let you define a custom server accessible from the outside by the Symantec Firewall/VPN 's external WAN IP address. The unit redirects all requests not explictily allowed by a virtual server rule to the exposed host. The Symantec Firewall/VPN then redirects the request to your internal local IP address for the virtual server. You should first check the Virtual Servers screen to make sure your server is not already predefined. For security reasons, make sure the exposed machine is "locked down" to prevent illegal access and compromise of the system. 4-22

  • 1
  • 2
  • 3
  • 4
  • 5
  • 6
  • 7
  • 8
  • 9
  • 10
  • 11
  • 12
  • 13
  • 14
  • 15
  • 16
  • 17
  • 18
  • 19
  • 20
  • 21
  • 22
  • 23
  • 24
  • 25
  • 26
  • 27
  • 28
  • 29
  • 30
  • 31
  • 32
  • 33
  • 34
  • 35
  • 36
  • 37
  • 38
  • 39
  • 40
  • 41
  • 42
  • 43
  • 44
  • 45
  • 46
  • 47
  • 48
  • 49
  • 50
  • 51
  • 52
  • 53
  • 54
  • 55
  • 56
  • 57
  • 58
  • 59
  • 60
  • 61
  • 62
  • 63
  • 64
  • 65
  • 66
  • 67
  • 68
  • 69
  • 70
  • 71
  • 72
  • 73
  • 74
  • 75
  • 76
  • 77
  • 78
  • 79
  • 80
  • 81
  • 82
  • 83
  • 84
  • 85
  • 86
  • 87
  • 88
  • 89
  • 90
  • 91
  • 92
  • 93
  • 94
  • 95
  • 96
  • 97
  • 98
  • 99
  • 100
  • 101
  • 102
  • 103
  • 104
  • 105
  • 106
  • 107
  • 108
  • 109
  • 110
  • 111
  • 112
  • 113
  • 114
  • 115
  • 116
  • 117
  • 118
  • 119
  • 120

4-22
Advanced Configuration
2.
Check or uncheck the
Enable
box to enable or disable your server.
Remember to click
Update Entery
if using with an existing virtual server.
3.
Enter your server LAN IP.
Virtual Servers need a local host with a static IP address to operate effectively.
Setup a
static local IP for your server using the Host IP & Group screen (or on the server itself).
Enter that IP here.
4.
Choose either TCP or UDP as the server protocol type.
5.
In the Port Ranges fields, enter the Start and Finish ports used by your server for both
Internal and External.
If only one port is used, enter the same number in both Start and Finish fields.
Usually
Internal and External should be the same, but you can Translate ports if different values
are entered (for example: 2000-2500 internally can be translated to 3000-3500 externally).
6.
Click
Add
to add a new entry or one of the following:
Click
Delete
to delete the entry shown and free up Symantec Firewall/VPN memory.
Click
Update
if you have changed the entry shown.
Click
Clear Form
before adding a new entry.
Exposed Host (DMZ)
This screen will let you define a custom server accessible from the outside by the Symantec
Firewall/VPN 's external WAN IP address.
The unit redirects all requests not explictily allowed by
a virtual server rule to the exposed host. The Symantec Firewall/VPN then redirects the request to
your internal local IP address for the virtual server.
You should first check the Virtual Servers
screen to make sure your server is not already predefined.
For security reasons, make sure the
exposed machine is “locked down” to prevent illegal access and compromise of the system.