Chapter 30 System
USG20(W)-VPN Series User’s Guide
559
30.7.5 Service Control Rules
Click
Add
or
Edit
in the
Service Control
table in a
WWW
,
SSH
,
Telnet
,
FTP
or
SNMP
screen to
add a service control rule.
Figure 381
Configuration > System > Service Control Rule > Edit
The following table describes the labels in this screen.
Edit
Double-click an entry or select it and click
Edit
to be able to modify the entry’s
settings.
Remove
To remove an entry, select it and click
Remove
. The USG confirms you want to
remove it before doing so. Note that subsequent entries move up by one when you
take this action.
Move
To change an entry’s position in the numbered list, select the method and click
Move
to display a field to type a number for where you want to put it and press [ENTER] to
move the rule to the number that you typed.
#
This is the index number of the service control rule.
The entry with a hyphen (-) instead of a number is the USG’s (non-configurable)
default policy. The USG applies this to traffic that does not match any other
configured rule. It is not an editable rule. To apply other behavior, configure a rule
that traffic will match so the USG will not have to use the default policy.
Zone
This is the zone on the USG the user is allowed or denied to access.
Address
This is the object name of the IP address(es) with which the computer is allowed or
denied to access.
Action
This displays whether the computer with the IP address specified above can access
the USG zone(s) configured in the
Zone
field (
Accept
) or not (
Deny
).
Authentication
Client Authentication
Method
Select a method the HTTPS or HTTP server uses to authenticate a client.
You must have configured the authentication methods in the
Auth. method
screen.
Apply
Click
Apply
to save your changes back to the USG.
Reset
Click
Reset
to return the screen to its last-saved settings.
Table 241
Configuration > System > WWW > Service Control (continued)
LABEL
DESCRIPTION
Table 242
Configuration > System > Service Control Rule > Edit
LABEL
DESCRIPTION
Create new
Object
Use this to configure any new settings objects that you need to use in this screen.
Address Object
Select
ALL
to allow or deny any computer to communicate with the USG using this service.
Select a predefined address object to just allow or deny the computer with the IP address
that you specified to access the USG using this service.
Summary of Contents for ZyWall USG20-VPN
Page 17: ...17 PART I User s Guide ...
Page 18: ...18 ...
Page 99: ...99 PART II Technical Reference ...
Page 100: ...100 ...