Network and System Management
391
ProSecure Unified Threat Management (UTM) Appliance
Each rule lets you specify the desired action for the connections that are covered by the rule:
• BLOCK always
• BLOCK by schedule, otherwise allow
• ALLOW always
• ALLOW by schedule, otherwise block
The following section summarizes the various criteria that you can apply to outbound rules in
order to reduce traffic. For more information about outbound rules, see Outbound Rules
(Service Blocking) on page 123. For detailed procedures on how to configure outbound rules,
see Set LAN WAN Rules on page 130 and Set DMZ WAN Rules on page 133.
When you define outbound firewall rules, you can further refine their application according to
the following criteria:
• Services. You can specify the services or applications, or groups of services or
applications to be covered by an outbound rule. If the desired service or application does
not display in the list, you need to define it using the Services screen (see Service-Based
Rules on page 123 and Add Customized Services on page 152).
• LAN users. You can specify which computers on your network are affected by an
outbound rule. There are several options:
- Any. The rule applies to all PCs and devices on your LAN.
- Single address. The rule applies to the address of a particular PC.
- Address range. The rule applies to a range of addresses.
- Groups. The rule applies to a group of PCs. (You can configure groups for LAN WAN
outbound rules but not for DMZ WAN outbound rules.) The Known PCs and Devices
table is an automatically maintained list of all known PCs and network devices and is
generally referred to as the network database, which is described in Manage the
Network Database on page 107. PCs and network devices are entered into the
network database by various methods, which are described in Manage Groups and
Hosts (LAN Groups) on page 106.
- IP Groups. The rule applies to a group of individual LAN IP addresses. Use the IP
Groups screen (under the Network Security main navigation menu) to assign IP
addresses to groups. For more information, see Create IP Groups on page 156.
• WAN users. You can specify which Internet locations are covered by an outbound rule,
based on their IP address:
- Any. The rule applies to all Internet IP address.
- Single address. The rule applies to a single Internet IP address.
- Address range. The rule applies to a range of Internet IP addresses.
- IP Groups. The rule applies to a group of individual WAN IP addresses. Use the IP
Groups screen (under the Network Security main navigation menu) to assign IP
addresses to groups. For more information, see Create IP Groups on page 156.
• Schedule. You can configure three different schedules to specify when a rule is applied.
Once a sched
ule is configured, it affects all rules that use this schedule. You specify the