Tek-Tips is the largest IT community on the Internet today!

Members share and learn making Tek-Tips Forums the best source of peer-reviewed technical information on the Internet!

  • Congratulations SkipVought on being selected by the Tek-Tips community for having the most helpful posts in the forums last week. Way to Go!

Creating an internet object

Status
Not open for further replies.

saffa2005

Technical User
May 24, 2005
8
0
0
GB
Hi,
What's the best way to create an 'Internet' network object that represent the www?

do i create a group of network addresses and exclude private netwrok ranges?

have a few machines on our DMZ that requires internet access only.. no internal access.

thanks in advance.
 
create a group with all you internal objects in it for destination, add it to the rule that will be your access to the internet. Right click on the object in the rule and selecte negate cell. so the rule would look something like
DMZnodes=>internalnets(negated)=>allowed services=>accept

cheers
 
thanks for the info..
however is it not deemed a 'risky' option to negate networks?
cheers
 
what rn4it's rule is doing, is to allow the DMZ machines to send traffic to any network EXCEPT the negated ones.
 
Another way of doing pretty much the same thing would be to have a rule saying

Source - Any
Destination - internal nets
service - any
action - drop

and then below it

source - DMZ servers
Destination - Any
Service - whatever services
Action - Accept

Obviously these would need to be positioned correctly in you policy so they don't drop valid traffic
 
Status
Not open for further replies.

Part and Inventory Search

Sponsor

Back
Top