The supposition you already initialized through the serial port the firewall 4000 (disposition connection IP, GUI to register jurisdiction and so on), and connected the good network according to above analysis situs chart, to found the related network object (for example to have question please to refer to “firewall 4000 management dispositions” and “firewall 4000 attribute dispositions” related documents or DEMO demonstration);
b. Request: Founds a user access strategy, in the permission in net region lihua can 4000 use ftp through the firewall the Server server to carry on the data transmission with the outside net region, and can maintain this company lengthening by joining time does not interrupt. Realizes the way to be as follows:
c. First selects “the network” in the firewall supervisor -> “the region” the menu, will spring the region management window, in the net region and outside the net region's default access authority will change “the default to forbid”;

d. Outside then the click “the high-level management” -> “the access strategy”, and selects the net region, clicks on the right key in the right side blank region, the selection “increases”:

e. Will then spring “the access strategy” the dialog box, the source chooses IP object lihua, the goal will be server, the service selects ftp and http, the control mode is “the permission”, the connection attribute hypothesis will be “the long connection”, the following chart will show:

f. Finally the complete strategy is as follows:

g. The detailed operation please refer to the DEMO demonstration.
Key word:
Based on zone control access strategy: In the firewall in 4000, each access strategy from belongs to some network region, describes in other region main engine region main engine to carry on time regarding the visit how should control; Each access strategy has the goal, the source, the movement surely; And in an access strategy speaking of the identical goal, may have the different source, each source may have the different access authority.
Knowledge spot:
Long connection: Speaking of the ordinary connection, if has not received the text to connect the overtime and to separate for a period of time, prevents the connection to accumulate more and more; But long connects not this limit, only if corresponds a side initiative demolition connection, otherwise the connection cannot separate. This function mainly uses, in certain must maintain in the online application, for example the ATM machine must maintain with the processing station server is connecting, this connection must establish as the long connection.
|