Instruction manual

Section 4, User Interface Guide NetVanta 2000 Series System Manual
60 © 2002 ADTRAN, Inc. 61200361L1-1E
> POLICIES > ACCESS POLICIES: TO DMZ > CONFIGURATION > POLICY CLASS
The P
OLICY
C
LASS
field is populated automatically by the NetVanta 2000 series using the current policy
class (VPN, Corporate Inbound, Corporate Outbound).
> POLICIES > ACCESS POLICIES: TO DMZ > CONFIGURATION > SOURCE IP
The S
OURCE
IP displays the source addresses of incoming traffic used for the policy. All IP records
previously defined in the IP table will appear in this drop down menu. Select the predefined IP record, or
choose
O
THER
and define the source IP using the IP and Mask Bits text boxes below the drop down menu.
A
NY
option in this menu represents all valid IP addresses in the Internet address space.
> POLICIES > ACCESS POLICIES: TO DMZ > CONFIGURATION > DESTINATION IP
The D
ESTINATION
IP displays the destination IP addresses of incoming traffic used for the policy. All IP
records previously defined in the IP table will appear in this drop down menu. Select the predefined IP
record, or choose
O
THER
and define the destination IP using the IP and Mask Bits text boxes below the
drop down menu.
A
NY
option in this menu represents all valid IP addresses in the Internet address space.
> POLICIES > ACCESS POLICIES: TO DMZ > CONFIGURATION > DESTINATION PORT
The D
ESTINATION
P
ORT
drop down menu lists all definitions made in the services table. Choose one of the
predefined destination port entries, or choose
O
THER
and define the destination port or port range using the
text boxes below the drop down menu. To define a single port, enter the desired port value in the port range
start text box and leave the port range text box empty.
A
NY
option in this menu represents the complete port
range from 1 to 65535.
> POLICIES > ACCESS POLICIES: TO DMZ > CONFIGURATION > PROTOCOL TYPE
The P
ROTOCOL
T
YPE
drop down menu selects the transport protocol for this access policy. If the desired
transport protocol is not listed in the menu, choose
O
THER
and enter the desired IP based transport protocol
number in the text box below the drop down menu.
> POLICIES > ACCESS POLICIES: TO DMZ > CONFIGURATION > ACTION TYPE
The A
CTION
T
YPE
menu defines the policy as a Permit or Deny policy. Permit policies allow traffic matched
by the policy selectors to pass through and Deny policies blocks that traffic.
> POLICIES > ACCESS POLICIES: TO DMZ > CONFIGURATION > TIME SCHEDULE USED
The T
IME
S
CHEDULE
U
SED
menu attaches a predefined time schedule to the Permit type access policy. This
activates the policy only in the time windows defined in the selected time schedule.
> POLICIES > ACCESS POLICIES: TO DMZN > CONFIGURATION > ENABLE LOG
The E
NABLE
L
OG
radio button selectively enables or disables event logging for the access policy.
> POLICIES > ACCESS POLICIES: TO DMZ > CONFIGURATION > ENABLE NAT
The E
NABLE
NAT radio button provides control to enable or disable NAT for the policy.