
Using PortShield Interfaces
14
Configuring PortShield Interfaces
SonicOS Enhanced 3.1 Release
Creating Transparent Mode PortShield Interfaces
You may find it useful to create address objects to bundle addresses into address objects and reference
these objects when creating a PortShield interface. Address objects allow for entities to be defined one
time and to be reused in multiple referential instances throughout SonicOS. The PortShield interface
creation environment provides a convenient way to reference address objects.
The following example takes a network with a series of addresses in the range 67.115.118.80/24 and
divides it into three PortShield Interfaces, mapping each to the following ports and address objects:
To create these PortShield interfaces, using the prescribed address objects, perform the following steps:
1. Click on the Networks->Interfaces option. The management software displays the Interfaces
Settings screen.
2. Click the Add PortShield Interface button. The management software displays the Add Port Shield
dialog box.
3. Click the Zone list box and click on a zone type option to which you want to map the interface. For
this exercise, click the LAN option. After you select a zone option, the management software
displays a more expanded version of the PortShield Interface Settings dialog box. Only interfaces
assigned to Trusted and Public zones can operate in Transparent mode.
4. Type a string in the PortShield Interface Name field.
5. Click on the IP Assignment list box and click the Transparent Mode option.
6. Click on the Transparent Range list box and click on the Create new address object option. The
management software displays the Add Address Object dialog box.
7. Fill out the fields as detailed in the next three sections to create the three different types of address
objects. The three scenarios presuppose you are in the 67.115.118.0 subnetwork.
PortShield Interface Port Numbers Mapped Address Object Type Address(es)
portshield1 5 Address Object Host 67.115.118.90/32
portshield2 12, 13, 14 Address Object Range 67.115.118.100-67
.115.118.102
portshield3 16, 20 Address Object Host
Group
67.115.118.200,
67.115.118.210,
67.115.118.212,
67.115.118.220,
67,115,118,230
Commentaires sur ces manuels