EasyManua.ls Logo

SonicWALL SMA - End Point Control

SonicWALL SMA
48 pages
Print Icon
To Next Page IconTo Next Page
To Next Page IconTo Next Page
To Previous Page IconTo Previous Page
To Previous Page IconTo Previous Page
Loading...
SonicWallSMAConnectTunnel12.0DeploymentPlanningGuide
PlanningYourVPN
22
DesignGuidelinesforAccessRules
Becausetheappliance processesyouraccesscontrolrulessequentially,theorderinwhichyouorganizethemis
significantintermsofwhetheraccessispermittedordenied.Carefullyreviewyoursecuritypolicysettingsto
avoidinadvertentlyplacingrulesinthewrongorder.
•Putyourmostspecificrulesatthetopof
thelist.Asageneralrule,itisbesttoputyourmostspecific
rulesatthetopofthelist.Puttingbroaderrulesthatgrantmorepermissionsatthetopofthelistmay
causetheappliancetofindamatchbeforeithasachancetoprocessyourmore
restrictiverules.
•BecarefulwithAnyrules.Ifyoucreatearulethatdoesnotrestrictaccesstoaparticularuseror
destinationresource,carefullyconsideritsimpactonpolicyrules.
Optimizingperformance.Becausetheapplianceevaluatesrulesinsequentialorder,youcanoptimize
performancebyplacingthenetworkresources
thatareaccessedmostfrequentlyatthetopofthelist.
•Avoidresourceandaccessmethodincompatibilities.Insomeveryspecificcases,certaincombinations
ofresourcetypesandaccessmethodscancreateproblemswithyouraccesspolicy.AMCvalidatesyour
ruleandnotifiesyouofpotentialproblemswhenyousaveit.
Referto“SecurityAdministration”inthe
InstallationandAdministrationGuidefordetailsonresolvingincompatibilityissues.
EndPointControl
YoucanuseEndPointControltoclassify devicesastheyattempttoconnecttotheappliance.Whenadevice
matchesaprofilethatyouhavecreated,itisassignedtoanEPCzoneoftrust,wherethedeviceisgranteda
certainamountofaccess,quarantined,ordeniedaccessaltogether.
Inaddition,onceadeviceisclassifiedintoa
givenzone,youcankeepcheckingitatasetintervaltoseeifitmeetsyourEPCrequirements.
AnEPCzonecanreferenceoneormoredeviceprofiles.Multipledeviceprofilesareusefulifuserswithsimilar
VPNaccessneeds
usedifferentcomputerplatforms.Forexample,youcouldconfigureanEPCzonethat
referencesadeviceprofileforWindowscomputers,andanotherzoneforMacintoshcomputers.
Zonesareinturnreferencedinacommunity,whichdetermineswhatdataprotectionagentsaredeployed.
Optionally,youcanreferenceazoneinanaccess
controlruletodeterminewhichresourcesareavailableto
usersinthatzone.
EPCevaluationprocessillustratestheEPCevaluationprocessperformedbytheSMAappliancewhenauser
connectstoit.
EPCevaluationprocess

Table of Contents

Related product manuals