About Security Policies
Firebox Vclass User Guide
163
automatically dumps the excess traffic and protects
your systems from stalling or crashing.
Multi-tenant
You can route VLAN traffic through a Firebox
Vclass appliance, including inter-VLAN
forwarding, or you can establish a number of user
domains to virtually define restricted groups of
network tenants and then route traffic to and from
the members of that domain.
Scheduling
You can establish hours and days for specific
actions that your appliance will take with certain
data, while allowing other data to pass unimpeded
or unaffected.
Policies with multiple actions
You can combine one or more actions in a policy. For exam-
ple, suppose you created a VPN policy that permits two
server-farm sites to share data with one another. You might
also want to implement load balancing, so that the data is
distributed equally among several servers. The required
policy would focus on the two gateway appliances as
source and destination and then apply both an IPSec action
and a load-balancing action.
Not all actions can be combined. The following table shows
the combinations of actions that can be applied in a single
policy.
Firewall
IPSec
Virtual
IP/NAT
Dynamic
NAT
Static
NAT
QoS
Firewall
na
YES
YES
YES
YES
YES
IPSec
YES
na
YES
YES
YES
YES
Virtual IP/
NAT
a
YES
YES
na
NO
NO
YES
Dynamic
NAT
YES
YES
NO
na
NO
YES
Summary of Contents for Firebox V10
Page 1: ...WatchGuard Firebox Vclass User Guide Vcontroller 5 0 ...
Page 32: ...xxxii Vcontroller ...
Page 40: ...CHAPTER 1 Introduction 8 Vcontroller ...
Page 52: ...CHAPTER 2 Service and Support 20 Vcontroller ...
Page 70: ...CHAPTER 3 Getting Started 38 Vcontroller ...
Page 110: ...CHAPTER 4 Firebox Vclass Basics 78 Vcontroller ...
Page 190: ...CHAPTER 7 Using Account Manager 158 Vcontroller ...
Page 268: ...CHAPTER 9 Security Policy Examples 236 Vcontroller ...
Page 410: ...CHAPTER 14 Monitoring the Firebox Vclass 378 Vcontroller ...
Page 456: ...CHAPTER 18 Using the Diagnostics CLI Feature 424 Vcontroller ...