To configure a single computer follow these steps:
Configuring IP Filter Lists and Filter actions
- Open an MMC window (Start > Run > MMC).
- Add the IP Security and Policy Management Snap-In.
- In the Select which computer this policy will manage window select the local computer (or any other policy depending upon your needs). Click Close then click Ok.
- Right-click IP Security Policies in the left pane of the MMC console. Select Manage IP Filter Lists and Filter Actions.
- In the Manage IP Filter Lists and Filter actions click Add.
- In the IP Filter List window type a descriptive name (such as HTTP, HTTPS) and click Add to add the new filters.
- In the Welcome window click Next.
- In the description box type a description if you want and click Next.
- In the IP Traffic Source window leave My IP Address selected and click Next.
- In the IP Traffic Destination window leave Any IP Address selected and click Next.
- In the IP Protocol Type scroll to TCP and press Next.
- In the IP Protocol Port type 80 (for HTTP) in the To This Post box, and click Next.
- In the IP Filter List window notice how a new IP Filter has been added. Now, if you want, add HTTPS (Any IP to Any IP, Protocol TCP, Destination Port 443) in the same manner.
- Now that you have both filters set up, click Ok.
- Back in the Manage IP Filter Lists and Filter actions review your filters (you can add or remove more filters later). Now we'd like to add a new filter that will define the INTRANET web traffic. Again, click Add.
- Again, give the new filter an appropriate name - for example - Intranet, and then proceed to configuring the filter by clicking Add.
- In the IP Traffic Source window leave My IP Address selected and click Next.
- In the IP Traffic Destination click the drop-down list and select the type of destination. For example, if you only want to allow web traffic for one specific Intranet web server called SERVER200, choose A Specific DNS Name.
Then, in the Host Name box type SERVER200 and click Next.
If you want to allow web traffic for an entire internal subnet such as 192.168.0.0/24, select A Specific IP Subnet, and type the Network ID and Subnet Mask for the required subnet. Click Next.
- Back in the IP Filter list add any other filter you want, and finally click Ok.
No comments:
Post a Comment