
Using PortShield Interfaces
26
Configuring PortShield Interfaces
SonicOS Enhanced 3.1 Release
–
Enable Dynamic Address Translation (DAT) is checked. With SonicPoint enforcement
disabled, this enables DAT for both wired and Wireless Guest Services.
• Warehouse: A custom zone for the Warehouse PortShield interface. General is a Wireless zone with
SonicPoint Enforcement disabled so it can be used like a LAN with mixed wired and wireless
clients.
–
Zone Type: Wireless.
–
All Security services enabled.
–
Only allow traffic generated by a SonicPoint is not checked, disabling SonicPoint
Enforcement. This setting allows the zone to be used for both wired and wireless traffic.
–
Enable Wireless Guest Services is not checked. Guest services is not enabled for the
Warehouse zone.
• DMZ: Default DMZ zone configuration.
–
Used for DMZ PortShield Group.
–
All SonicWALL Security Services enabled.
• Kiosk: Copy of DMZ zone configuration.
–
Used for Kiosk PortShield.
–
All SonicWALL Security Services enabled.
PortShield Groups
The small business example uses six PortShield interfaces.
• Administration: for business office use, HR, Accounting, and Billing departments
–
LAN zone
–
5 ports, 2 - 6
–
10.100.23.0 subnet
–
Accounting, Billing, HR, etc.
–
Accounting Server 10.100.23.2
–
HR Server 10.100.23.3
–
3 desktop workstations
–
no wireless access
• General Users
–
General custom Wireless zone with SonicPoint enforcement disabled
–
7 ports, 7 - 13.
–
172.16.1.0 subnet.
–
4 desktops.
–
Server for sales software 172.16.1.2.
–
One SonicPoint for wireless access for employees.
–
Wireless Guest Services enabled--both wireless and wired.
–
One Guest port in conference room.
• Warehouse
Komentarze do niniejszej Instrukcji