Policy Configuration : Understanding the Network Access Rules Hierarchy

Configuring Rules in SonicOS Standard
To configure rules for SonicOS Standard, complete the following steps:
1
2
3
Adding a Service
By default, a large number of services are pre-defined. This section describes how to add a new or custom service.
To add a service, complete the following steps:
1
2
Expand the Firewall tree and click Services. The Services page displays.
 
3
To add a known service (e.g., HTTP, FTP, News), select the service from the Service Name list box and click Add Known Service. Repeat this step for each service that you would like to add. A task is scheduled for each service for each selected SonicWALL appliance.
4
To add a custom service, enter its name in the Service Name field, enter the port range it uses in the Port Begin and Port End fields, select the appropriate protocol check boxes, and click Add Custom Service. Repeat this step for each service that you would like to add. A task gets scheduled for each service for each selected SonicWALL appliance.
5
To remove a service from the list, select its trash can check box and click Update. A task gets scheduled to update the services page for each selected SonicWALL appliance.
6
Creating Rules
This section describes how to define rules for defined services in SonicOS Standard.
To create a rule, complete the following steps:
1
2
Expand the Firewall tree and click Rules. The Rules page displays.
 
3
Click Add Rule. The Add Rule dialog box displays.
4
Select a service from the from the Service Name list box. If the service does not exist, refer to Adding a Service .
5
6
7
To apply the rule to a range of IP addresses, enter the first and last IP addresses of the range in the Addr. begin field and Addr. End fields, respectively. The rule applies to requests originating from IP addresses within this range. For all IP addresses, enter an asterisk (*).
8
9
10
a
Enter the amount of bandwidth that is always be available to this service in the Guaranteed Bandwidth field. Keep in mind that this bandwidth is permanently assigned to this service and not available to other services, regardless of the amount of bandwidth this service does or does not use.
b
c
Select the priority of this service from the Bandwidth Priority list box. Select a priority from 0 (highest) to 7 (lowest).
11
To add this rule to the rule list, click Update. Repeat Step 3 through Step 11 for each rule that you want to add.
12
13
If the network access rules for a SonicWALL appliance need to be uniform with access rules for other SonicWALL appliances in the same group, you can restore the group rules. To do this, click Restore Rules to Group Settings and click Update. A task is scheduled to overwrite the rules page for each selected SonicWALL appliance. If you want to append the group rules to the current rules, make sure Append Services and Rules inherited from group is selected on the GMS Settings page of the Console Panel.
14
To modify a rule, select its notepad icon. The Add/Modify Rule dialog box displays. When you are finished making changes, click Update. Dell SonicWALL GMS creates a task that modifies the rule for each selected SonicWALL appliance.
15
16
To delete a rule, select its trash can icon and click Update. Dell SonicWALL GMS creates a task that deletes the rule for each selected SonicWALL appliance.