Policy Configuration : Configuring Access Rules

Configuring Access Rules
To configure rules for SonicOS Enhanced, the service or service group that the rule applies to must first be defined. If it is not, you can define the service or service group and then create one or more rules for it.
The following procedure describes how to add, modify, reset to defaults, or delete firewall rules for SonicWALL firewall appliances running SonicOS Enhanced. For appliances running SonicOS Enhanced, GMS supports paginated navigation and sorting by column header on the Access Rules screen. In the Access Rules table, you can click the column header to use for sorting. An arrow is displayed to the right of the selected column header. You can click the arrow to reverse the sorting order of the entries in the table.
By hovering your mouse over entries on the Access Rules screen, you can display information about an object, such as an Address Object or Service.
IPv6 is supported for Access Rules. Search for IPv6 Access Rules in the Access Rules Search section. A list of results displays in a table.
From there you can click the Configure icon for the Access Rule you want to edit. The IPv6 configuration for Access Rules is almost identical to IPv4.
To configure an access rule, complete the following steps:
1
2
Expand the Firewall tree and click Access Rules. The Access Rules page displays. The Firewall > Access Rules page enables you to select multiple views of Access Rules, including drop-down boxes, Matrix, and All Rules. The default view is the Matrix View that provides a matrix of source and destination nodes between LAN, WAN, VPN, Multicast, and WLAN.
 
3
From the Matrix View, click the Edit icon (). for the source and destination interfaces for which you will configure a rule. The Access Rules table for that interface pair displays.
4
The Add Rule dialog box displays.
 
5
6
Select the from and to zones from the From Zone and To Zone menus.
7
Select a service from the from the Service Name list box. If the service does not exist, refer to Configuring Service Objects .
8
9
10
11
12
13
Check Allow Fragmented Packets to allow fragmented packets.
14
(optional) Click Don’t invoke Single Sign ON to Authenticate Users. This option is available when Enable SSO agent authentication is clicked in the Users > Settings screen. This option is disabled when All is selected from the Users Included drop-down and None is selected from the Users Excluded drop-down.
15
(optional) Click Enable Management. If this option is enabled, both management and non-management traffic is allowed.
16
17
Click the Advanced tab.
 
18
19
20
Specify the percentage of the maximum connections this rule is to allow in the Number of connections allowed (% of maximum connections) field.
21
Set a limit for the maximum number of connections allowed per source IP Address by selecting Enable connection limit for each Source IP Address and entering the value in the Threshold field.(Only available for Allow rules).
22
Set a limit for the maximum number of connections allowed per destination IP Address by selecting the Enable connection limit for each Destination IP Address field and entering the value in the Threshold field. (Only available for Allow rules).
23
Click the QoS tab. For information on configuring the QoS tab, refer to Configuring Quality of Service Mapping .
24
Click the Bandwidth tab. The Bandwidth page displays.
 
25
26
a
Enter the amount of bandwidth that is always available to this service in the Guaranteed Bandwidth field, and select either % or Kbps in the pull-down list. Keep in mind that this bandwidth is permanently assigned to this service and not available to other services, regardless of the amount of bandwidth this service does or does not use.
b
c
Select the priority of this service from the Bandwidth Priority list box. Select a priority from 0 (highest) to 7 (lowest).
27
a
Enter the amount of bandwidth that is always available to this service in the Guaranteed Bandwidth field, and select either % or Kbps in the pull-down list. Keep in mind that this bandwidth is permanently assigned to this service and not available to other services, regardless of the amount of bandwidth this service does or does not use.
b
c
Select the priority of this service from the Bandwidth Priority list box. Select a priority from 0 (highest) to 7 (lowest).
28
29
To add this rule to the rule list, click OK. You are returned to the Access Rules page.
30
31
To modify a rule, click its Edit icon (). The Add/Modify Rule dialog box displays. When you are finished making changes, click OK. Dell SonicWALL GMS creates a task that modifies the rule for each selected SonicWALL appliance.
32
33
34