1. All inbound access from the external network is denied.
2. All access from the external network to the GTA firewall is denied.
3. Access to the GTA firewall using the web interface is allowed only from IP addresses on the protected network. 4. Access from a Private Service Network to the GTA firewall is denied.
5. Access from a Private Service Network to a protected network is denied. 6. Access to the console interface requires a user ID and password. 7. Access to the web interface requires a user ID and password.
Remote Access Filters
1 #DEFAULT: Allow Protected Network access to remote admin services. Accept notice “PROTECTED” TCP from ANY _ IP to ANY _ IP 443 77
2 #DEFAULT: Allow Protected Network access to DNS server. Accept notice “PROTECTED” UDP from ANY _ IP to ANY _ IP 53
3 #DEFAULT: Allow Protected Network access to SNMP service. DISABLED - Accept notice “PROTECTED” UDP from ANY _ IP to ANY _ IP 161
4 #DEFAULT: DNSproxy - Allow all DNS replies. Accept notice ANY UDP from ANY _ IP 53 to ANY _ IP 53
5 #DEFAULT: DNS server - Allow all DNS replies. DISABLED - Accept notice ANY UDP from ANY _ IP 53 to ANY _ IP 1024:65535
6 #DEFAULT: Allow access to user authentication server. DISABLED - Accept notice ANY TCP from ANY _ IP to ANY _ IP 76
7 #DEFAULT TRADITIONAL URL PROXY: Allow connections to URL proxy. DISABLED - Accept notice “PROTECTED” TCP from ANY _ IP to 0.0.0.0/0 2784
8 #DEFAULT EMAIL PROXY: Allow connections to email proxy. DISABLED - Accept notice “EXTERNAL” TCP from ANY _ IP to ANY _ IP 25
9 #DEFAULT: Block/nolog discard bootp, netbios, and rwho. Deny warning ANY UDP nolog from ANY _ IP to ANY _ IP 9 67 68 137 138 513
10 #DEFAULT NO RIP: Block/nolog rip. Deny warning ANY UDP nolog from ANY _ IP to ANY _ IP 520 11 #DEFAULT RIP: Accept UDP rip. DISABLED - Accept notice ANY UDP from ANY _ IP to ANY _ IP 520
12 #DEFAULT RIP: Accept IGMP multicast for router addresses. DISABLED - Accept notice ANY 2 from ANY _ IP to 224.0.0.0/24
164 GB-OS 3.7 User’s Guide
13 #DEFAULT RIP: Accept router solicitations and advertisements DISABLED - Accept notice ANY ICMP from ANY _ IP to 224.0.0.0/24 9 10
14 #DEFAULT STEALTH: Block with alarm any other access to external interface. DISABLED - Deny warning “EXTERNAL” ALL alarm from ANY _ IP to ANY _ IP
15 #DEFAULT: Accept/nolog authentication (ident). Accept notice ANY TCP nolog from ANY _ IP to ANY _ IP 113 16 #DEFAULT: Allow pings and ICMP traceroutes to GB-OS. Accept notice ANY ICMP from ANY _ IP 8 to ANY _ IP 8 17 #DEFAULT: Allow UDP traceroutes to GB-OS. Deny warning ANY UDP nolog genICMP from ANY _ IP to ANY _ IP 32767:65535
18 #DEFAULT: Block/nolog stale WWW accesses. Deny warning ANY TCP nolog from ANY _ IP 80 to ANY _ IP 1024:65535 19 #DEFAULT: Block with alarm any other access to all interfaces. Deny warning ANY ALL alarm from ANY _ IP to ANY _ IP
account 5, 29, 47, 49, 50, 72, 131, 144
administrator 47
user 2, 47, 49, 53, 54, 55, 76, 111, 114, 122, 123, 145, 147, 160
ACL 31, 33, 34, 35, 37, 41, 42, 59, 60, 62, 116, 117, 118, 131, 132, 144, 145.
See also
access control listmatch 131
Acrobat Reader ii, 3.
See also
Adobeactivation code 2, 5, 13, 14, 26, 29, 30, 33, 59, 131, 150 ActiveX 59, 60.
See also
content filteringadministrator 15, 23, 27, 29, 42, 45, 47, 48, 60, 61, 74, 82, 85, 89, 96, 103, 105, 109, 115, 142, 150, 151, 159.
See also
ac- countAdobe ii, 3.
See also
documentation Adobe Acrobat Reader ii, 3AES 1, 55, 79
AH 57, 82, 83, 95, 96.
See also
VPNalarm notifications 29, 85, 86, 87.
See also
filtersmuffle benign events 89
aliases 27, 28, 95, 156, 158, 159 AOL 132
Apple 3, 6, 8, 52.
See also
Macintosh applets 59, 60.See also
JavaARP table 101, 108, 111.
See also
router ASCII 30, 54, 55, 56, 57asterisk 73, 112.
See also
regular expressions attacks.See
vulnerabilitydoorknob twist 86, 98 fragmented packets 85, 86 ICMP replay 86 invalid packets 85, 86 IP address spoof 85, 86 authentication 1, 45, 48, 49, 50, 52, 53, 54, 56, 57, 78, 79, 82, 114, 122, 123, 124, 131, 134, 146, 159, 163, 164 authorization 45, 48, 53, 54, 55, 132, 149, 152 A records 27.
See also
DNSB
backup 5
bandwidth 29, 74, 75, 82, 96
beacon IP addresses 63, 64.
See also
failover black list 31, 35, 37, 131, 132.See also
Mail Sentinelreal-time 131
Blowfish 1, 55 bridge 2, 16, 17, 93
bridged interfaces 16, 93.
See also
bridge bridged protocol.See
protocolbridging 2, 15, 17, 30, 67, 91, 92, 130, 157 broadcast 68, 112, 129
browser 1, 8, 9, 52, 53, 102, 103, 142, 143, 149, 150, 152
Internet Explorer ii, 8, 52, 53, 128, 149, 152 Mozilla 8, 52, 149
Netscape Navigator 8, 52, 149
confirmed spam 33.
See also
Mail Sentinel Anti-Spam Connection Time-out 20connectivity tests.
See
ping;See
tracerouteconsole 1, 3, 5, 8, 44, 47, 50, 51, 52, 102, 128, 129, 133, 141, 142, 149, 151, 163
content filtering 1, 3, 59, 60, 62, 143 copyright ii
cracks 91, 155, 156.
See also
vulnerability;See also
virtual crackcrossover cable 5, 7, 128, 130, 131
D
database conversion.
See
DBmanagerDB-9 128.
See
serial cable;See also
serial cable DBmanager 3, 44, 121, 122 DDNS.See
dynamic DNS default address objects 74 filter 19, 49, 62, 92, 137 IP address 8, 11 network settings 6 password 8, 11 ports 133 route 6, 9, 12, 15, 16, 17, 25, 63, 68, 69, 127, 129, 158 security mode 11, 12 user ID 8, 9, 11, 47, 149 VPN objects 55, 76 deny 2, 31, 33, 35, 37, 49, 57, 59, 60, 82, 83, 93, 131, 137, 138, 146, 147 DES 1, 55 DHCP 1, 2, 9, 12, 15, 16, 18, 25, 26, 76, 78, 111, 115 dial-up 18, 19, 49 dial scripts 18 Diffie-Hellman groups 2, 78, 79, 80 disconnected cable 130, 137 distinguished name.See
DN DMZ 1, 9, 12, 17, 156, 157 DN 48, 124 DNS 1, 2, 6, 9, 12, 13, 20, 25, 26, 27, 28, 29, 31, 33, 41, 42, 52, 53, 59, 67, 72, 84, 87, 102, 104, 115, 117, 127, 131, 133, 134, 144, 155, 160, 161, 163 dynamic 28, 29, 133 lookup 33, 41 proxy 2, 13 record 27, 28 server 9, 12, 13, 20, 25, 26, 27, 28, 33, 41, 42, 53, 59, 87, 160, 161, 163 documentation ii, 3, 5, 6, 25, 155, 157 domain name 9, 12, 13, 15, 16, 25, 26, 27, 28, 41, 48, 49, 50, 59, 61, 72, 73, 78, 87, 102, 104, 129, 131, 132, 145 qualified 15, 16, 50, 102, 145dotted decimal notation 9, 10, 102 download 3, 101
166 GB-OS 3.7 User’s Guide
DSL 18, 20 duplex 17
dynamic DNS 28, 29, 133.
See also
DNSE
address ii, 33, 54, 56, 78, 87, 108, 116, 117, 118, 123, 131, 132, 145
black list 35.
See also
black list block 35.See also
black list destination 35filtering 1 headers 145
proxy 2, 25, 31, 33, 35, 37, 41, 42, 67, 72, 87, 116, 117, 130, 131, 132, 144, 145, 163.
See also
Mail Sentinelserver 2, 28, 31, 33, 35, 72, 87, 130, 131, 132, 144, 157 source 35
white list 35.
See also
white listencapsulation 19, 79, 155
encryption 1, 8, 18, 45, 50, 51, 52, 55, 57, 68, 78, 79, 80, 142, 149, 159
errors ii, 71, 102, 107, 108, 109, 127, 128, 131, 132, 137, 145.
See also
self-verification;See also
problemsESP 57, 79, 82, 83, 95, 96, 113.
See also
IPSec;See al-
so
VPNEthernet 1, 2, 5, 6, 7, 16, 17, 18, 91, 93, 101, 157.
See
also
straight-through cable;See also
crossover cableF
factory setting 127 failover 1, 30, 63, 64, 67
feature activation code 2, 5, 30, 59, 150
filters 1, 2, 9, 16, 45, 49, 50, 53, 57, 62, 63, 72, 74, 75, 76, 81, 82, 83, 84, 85, 86, 88, 89, 90, 91, 92, 93, 95, 96, 97, 101, 108, 112, 129, 130, 132, 133, 139, 147, 150, 159, 160, 163 bypass 16, 31, 59, 91, 93, 137 matched 81 order of evaluation 131 schedules 90 flow control 18, 128
fragmented packets.
See
attacksFTP 1, 28, 44, 50, 59, 74, 75, 76, 81, 91, 134, 138, 139, 140, 155, 156, 157 updated port 138
G
gateway 1, 2, 6, 15, 16, 17, 18, 19, 25, 55, 56, 57, 63, 64, 65, 66, 67, 68, 69, 76, 78, 80, 91, 104, 112, 113, 127, 137, 138, 158, 160 policies 67gateway-to-gateway 1, 55.
See also
VPNGB-Commander ii, 3, 25, 29, 30, 103, 121, 122, 133, 147 Server 25, 29, 30, 133 GB-Ware ii, 5, 14 GBAdmin 1, 3, 5, 6, 8, 11, 12, 14, 15, 16, 17, 18, 20, 26, 28, 29, 30, 47, 50, 51, 52, 56, 72, 73, 81, 101, 103, 104, 107, 108, 109, 111, 128, 129, 133, 141, 142, 149, 152, 153, 154 GBAuth 1, 3, 48, 49, 50, 78, 82, 96, 114, 122, 123, 124, 132, 133, 147
generic routing encapsulation 19.
See also
GRE gigabit 2, 17GMT 42, 103
GNAT Box Mailing List 2
GNAT Box System Software 1, 3, 4, 5, 10, 18, 45, 52, 68, 74, 103, 104, 105, 121, 128, 137, 149, 155, 156, 157, 158, 160 GRE 19, 83
GTAsyslog 1, 3, 43, 44, 121, 122, 137
GTA Channel Partner 2, 60 GTA Mobile VPN Client.
See
VPN GTA online support center 2, 5, 14GTA Reporting Suite 3, 29, 43, 44, 103, 121, 122, 137 GTA Sales 2
H
H2A 1, 3, 17, 25, 29, 30, 31, 78, 96, 159
H2A High Availability 1, 3, 17, 25, 29, 30, 31, 159 halt 101, 102.
See also
shut downHEX 30, 54, 56, 57.
See also
hexadecimal hexadecimal 14, 54, 55, 56, 57, 93 holes.See
crackshops 63, 64, 67, 68.
See also
routerhost name 13, 15, 16, 27, 28, 29, 30, 41, 42, 43, 48, 52, 53, 86, 87, 104, 134, 145, 149, 152.
See also
domain name HTTP 44, 45, 50, 51, 52, 59, 60, 61, 62, 81, 133, 134, 139,140, 141, 143, 155.
See also
URL;See also
Surf Sentinel 2.0;See also
browser;See also
HTTPSproxy 59, 61, 62, 133, 143 unknown commands 59, 60 HTTPS 51, 52, 133, 134.
See also
SSL hub 5, 6, 8, 52, 128, 130I
IANA 93, 96, 133, 134 ICMP 63, 67, 82, 84, 85, 86, 95, 96, 98, 102, 104, 114, 137, 139, 140, 142, 147, 155, 160, 164 IETF 50, 77, 160 IGMP 82, 83, 95, 96, 163IKE 54, 56, 57, 76, 78, 79, 80, 145, 160.
See also
VPN indicator 8, 154insecure 8, 52, 160
installation ii, 2, 3, 5, 14, 53, 121, 152, 155, 158 Internet Engineering Task Force.
See
IETF Internet Explorer ii, 8, 52, 53, 128, 149, 152 IPSec 1, 2, 56, 57, 77, 80, 160.See also
VPN IP aliases.See
aliasesIP packet.
See
packet ISDN 20, 21ISP 13, 16, 25, 27, 28
J
Java ii, 1, 59, 60, 122, 132
JavaScript 59, 60.
See also
content filtering jumbo packets 17junk email.
See
spamK
key length 55 keyboard shortcuts 153L
LAN 5, 7LCLs.
See
local content lists LCP 21LDAP 48, 49, 50, 78, 114, 122, 124, 133, 134.
See also
au- thenticationlease 25, 113, 114
expired 20, 111, 113, 115, 145, 146
LED 8
license 113, 114, 117, 121, 122, 145, 147 Lightweight Directory Access Protocol.
See
LDAPLinux ii, 44.
See also
Unix;See also
Macintosh;See also
Win- dowsM
Macintosh 6, 8, 52, 149 MAC address 17, 111
Mac OS X.
See
Macintosh;See also
Apple Mail Sentinel 131Mail Sentinel Anti-Spam 1, 31, 33, 35, 116, 117, 131, 132, 144, 145
Mail Sentinel Anti-Virus 1, 31, 33, 35, 116, 117, 118, 131, 132, 144, 145
malicious programs 60.
See also
virus manual key exchange 56.See also
IKEMAPS 31, 33, 41, 42, 72, 117, 131, 132, 144.
See also
black listmatching rules.
See
regular expressionsMatch Against MX.
See
access control list;See also
MX records maximumfile size 31, 33, 117, 131
MD5 55, 68.
See also
hash memory slice 128, 129 MicrosoftExchange server 129, 130
Windows ii, 1, 6, 7, 8, 11, 29, 52, 53, 121, 122, 123, 124, 125, 128, 130, 135, 149, 152, 153, 154, 156.
See also
LinuxMTU 17, 21 multi-WAN 2
MX records 27.
See also
DNSN
NAS 48, 49.
See also
RADIUSNAT 1, 2, 43, 44, 45, 67, 78, 79, 82, 88, 89, 91, 92, 93, 95, 97, 111, 113, 138, 139, 140, 141, 143, 144, 146, 147, 155, 157, 158, 159, 160
NAT-T 2, 78
NAT traversal.
See
NAT-Tnavigation 150.
See also
user interfaces NetBIOS 129, 130, 134, 156.See also
Windows network class 10, 15 connection type 127 settings 5, 6, 8, 9, 12 type 9, 12, 15, 95, 156 external 157 protected 157 PSN 157network time server 9
NIC 6, 7, 9, 15, 16, 17, 18, 19, 20, 95, 138, 157, 158, 159 NIC 0 6, 7, 9 NTP 9, 42, 67, 132, 133, 134 server 42 parity 18 passthrough 16, 49, 50, 74, 75, 76, 81, 91, 92, 95, 112.
See
also
NAT password 5, 8, 9, 11, 20, 21, 29, 45, 47, 49, 50, 54, 68, 101, 115, 122, 123, 124, 125, 128, 132, 141, 142, 149, 152, 163 administrative 11 PDC 129 percentage 74, 96, 116 Phone Number 20, 23, 29, 88 ping 63, 64, 67, 86, 101, 102, 103, 104, 127, 128, 129, 130, 131, 142, 160policy-based routing 63, 66.
See also
gateway;See also
filters pool 25ports 3, 6, 16, 49, 59, 60, 82, 87, 88, 89, 91, 97, 132, 133, 134, 142, 155
registered 133, 134.
See also
port number TCP 133port number 29, 30, 43, 48, 51, 62, 75, 83, 122, 133, 149.
See
also
protocol PPP 1, 2, 13, 15, 16, 17, 18, 19, 20, 21, 22, 23, 76, 78, 127, 137, 158 PPPoE 1, 15, 17, 18, 20, 21, 23, 127, 137 Provider 21 PPTP 1, 15, 17, 18, 19, 20, 21, 23, 127 Primary Domain Controller.See
PDCpriority 28, 30, 35, 37, 44, 45, 63, 74, 82, 83, 85, 86, 138, 141, 160 problems 5, 33, 69, 107, 112, 127, 131, 132, 137, 154, 155 protocol 1, 16, 17, 18, 21, 43, 50, 55, 57, 59, 65, 68, 69, 75, 79, 81, 82, 83, 84, 88, 89, 91, 93, 95, 97, 98, 101, 102, 114, 137, 138, 141, 155, 156, 159, 160 bridged 137 proxy DNS 2, 13 email 1, 2, 25, 31, 33, 35, 37, 41, 42, 67, 72, 87, 116, 117, 130, 131, 132, 144, 145, 163 HTTP 59, 61, 62, 133 port 61 SMTP 115 traditional 61, 62, 143 transparent 61, 143 PSN 1, 2, 9, 12, 15, 16, 20, 25, 56, 57, 68, 78, 82, 83, 87, 89, 91, 95, 96, 97, 98, 113, 129, 130, 141, 155, 156, 157, 158, 159
Q
quarantine 35, 72, 116, 117, 118, 131, 144, 145.
See al-
so
spam;See also
virusquestion mark 73.
See also
regular expressionsR
RADIUS 48, 49, 50, 78, 114, 122, 124, 125, 133.
See also
au- thentication168 GB-OS 3.7 User’s Guide
ranges 2, 25, 27, 72, 131, 133 RBL.
See
black listRDNS.
See
reverse DNS references.See
objects register 2, 5registration 3, 5, 14
regular expressions 72, 73, 74, 131.
See also
objectsremote access filter 13, 19, 42, 48, 49, 50, 51, 62, 78, 86, 89, 97, 122, 123, 124, 128, 129, 130, 138, 141
remote administration 50, 51, 52, 141, 142, 149.
See also
re- mote managementRemote Authentication Dial-In User Service.
See
RADIUS remote logging 1, 43, 137remote management 1, 141, 142
reports 2, 23, 45, 54, 103, 107, 108, 111, 113, 114, 127, 131, 132, 150.
See also
system activityreset to factory defaults 101, 128, 149
reverse DNS 27, 28, 31, 33, 41, 117.
See also
DNS reverse zone names 27, 28revert 128, 129.
See also
reset RFC 1058 68RFC 2401 77
RIP 17, 63, 68, 69, 82, 130, 163, 164 RJ-45 157.
See also
EthernetRMC 47, 50, 51, 133, 141, 142, 149.
See also
GB-Com- manderrouter 2, 5, 9, 12, 16, 17, 20, 25, 69, 91, 101, 127, 128, 130, 163, 164
Routing Information Protocol.
See
RIP rule.See
filtersruntime (executable) 105, 128, 153.
See also
software versionS
SA 54, 55, 146.
See also
VPNscripts 18, 59, 60.
See also
content filtering security alert 8, 52, 123security association.
See
SA security certificate 8, 52, 53security policy 19, 56, 57, 83, 86, 88, 97, 150, 160 self-verification 108.
See also
errorsserial cable 5
serial console 128.
See also
user interfaces serial number 2, 5, 13, 14services 1, 3, 6, 13, 14, 25, 26, 28, 41, 48, 50, 67, 82, 89, 96, 102, 129, 132, 133, 134, 155, 157, 163
SHA1 78, 79.
See also
hash shut down 102, 156Simple Network Management Protocol.
See
SNMP SMB 156.See also
NetBIOSSMTP 31, 41, 72, 81, 115, 117, 118, 132, 134, 144, 145 SNMP 25, 45, 47, 82, 87, 134, 163
software version 104, 128
spam 1, 3, 31, 33, 35, 41, 116, 117, 131, 144, 145
Unkown status 117
SPI 55.
See also
VPNSSL 1, 8, 9, 12, 16, 48, 50, 51, 52, 53, 123, 131, 132, 133, 134, 142, 149
certificate 8, 9, 12, 16, 52, 53, 123, 132
SSL-compatible 1, 8, 52, 149
Stateful Packet Inspection engine 1, 155 static address mapping 97, 158.
See also
NAT static mapping.See
static address mapping stealth mode 1, 81, 84, 86, 160straight-through cable 5, 128, 130, 131 subject line tags.
See
tagsubnet mask 6, 10, 15, 25, 27, 28, 54, 56, 57, 69, 71, 72, 93, 95, 98, 159
support ii, 1, 2, 5, 23, 26, 43, 50, 52, 91, 107, 108, 143, 146, 147, 155, 158, 159, 160
Surf Sentinel 2.0 ii, 1, 44, 59, 60, 132, 143, 147 switch 5, 6, 8, 17, 67, 122, 128, 130
syslog 1, 43, 44, 122, 134
system activity 43, 54, 63, 96, 97, 111, 115, 118, 131, 132, 147
T
tag 16, 35, 138, 139, 141, 142.
See also
Mail Sentinel Anti-Vi- rus;See also
Mail Sentinel Anti-Spamtagging.
See
tagTCP 1, 6, 16, 30, 31, 43, 49, 50, 51, 60, 62, 65, 68, 81, 82, 86, 93, 95, 96, 98, 114, 115, 122, 129, 130, 131, 132, 133, 134, 135, 137, 138, 139, 140, 141, 142, 143, 147, 155, 163, 164 technical support.
See
supporttelnet 2, 97, 134, 155 terminal 128 emulation 128 testing connectivity 127 threads 145
timeout 95, 98, 99, 113, 114, 116, 117.
See also
lease time zone 42, 103.See also
NTPtopographies 2
total number 54, 116, 117, 118 traceroute 101, 104, 127 trademarks ii
traditional proxy 61, 62, 143
traffic shaping 74, 75, 76, 82, 96.
See also
bandwidth transparent proxy 61, 143 troubleshooting 3, 84, 101, 107, 112, 116, 127, 128, 129 connectivity 127 tunnel 31, 45, 49, 50, 74, 75, 76, 81, 84, 86, 88, 89, 95, 96, 97, 122, 129, 138, 139, 141, 146, 147, 155, 156, 157, 159, 160 TX_100 17U
UDP 1, 42, 57, 65, 66, 82, 86, 95, 96, 98, 104, 114, 129, 130, 133, 134, 135, 137, 138, 139, 140, 141, 142, 155, 160, 163, 164Unix 44, 149.
See also
Linux;See also
Macintosh;See
also
Windowsunlocking.
See
DBmanager unsolicited email.See
spamupdate 2, 5, 16, 28, 51, 52, 104, 105, 111, 112, 114, 116, 128, 131, 132, 133
upgrade.
See
updateupload 104, 105.
See also
updateURL 44, 45, 50, 51, 60, 61, 62, 143, 149, 163.
See also
con- tent filtering user ID 5, 8, 9, 11, 20, 47, 50, 141, 149, 163 user interfaces 1, 3, 141, 149 UTC 42, 103 utility software 3, 6, 48, 137 UTP_10 17V
verification 108, 109, 127, 141, 142, 150, 152, 154.See
also
errorsversion.
See
software versionvirtual crack 75, 76, 155, 156.
See also
cracks Virtual Router ID.See
VRIDvirus ii, 1, 3, 31, 33, 35, 116, 117, 118, 131, 132, 144, 145.
See
also
Mail Sentinel Anti-Virus153, 154, 163
web server 2, 28, 102, 103, 138, 139, 141, 149, 158 web site ii, 2, 3, 14, 28, 59, 62, 91, 93, 129, 133, 150, 155 weight 74, 75, 76, 134, 163.
See also
priorityWELF ii, 43, 119, 121, 137.
See also
log white list 31, 35, 37, 132.See also
Mail Sentinel wild-card character 73.See also
regular expressionsWindows ii, 1, 6, 7, 8, 11, 29, 52, 53, 121, 122, 123, 124, 125, 128, 130, 135, 149, 152, 153, 154, 156
Windows-compatible 1, 29
X
X-headers 145.