This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

What are the best practices when setting up policies?

Hi everybody,

when creating your policies, do you eventually disable the default firewall policy (#Default_Network_Policy)? Or do you disable it from the beginning?

If I remember the old practice, all ports should be closed by default and only the needed ones should be then opened.

The XG Firewall I am configuring is for a small-medium size business. I don't want to spend too much time on configuring the policies but a minimum should be done.

How do you proceed, and why?

Tks

 



This thread was automatically locked due to age.
Parents
  • Hi,

    You can find a lot of help with your setup from the XG's how-to videos and the administrative guide

    Thanks

  • Hi,

    My question was not about "how to create policies" but rather what to do with the default policy. Sorry but I don't remember seeing anything about that in the videos or admin guide.

  • The policy that you refer to #Default_Network_Policy is the default firewall rule to process traffic coming from the internal network and going through the XG firewall.

    XG firewall follows TOP-DOWN approach while searching for a firewall rule. Always remember to configure the custom rules on the TOP. You can simply edit and configure your custom policies in this rule and define the custom ports and services allowed through the firewall, in case you need a quick setup with fewer rules to manage. Select suitable filter policies in the rule to filter the outgoing traffic and that serves the purpose. 

    I hope that answers the question.

Reply
  • The policy that you refer to #Default_Network_Policy is the default firewall rule to process traffic coming from the internal network and going through the XG firewall.

    XG firewall follows TOP-DOWN approach while searching for a firewall rule. Always remember to configure the custom rules on the TOP. You can simply edit and configure your custom policies in this rule and define the custom ports and services allowed through the firewall, in case you need a quick setup with fewer rules to manage. Select suitable filter policies in the rule to filter the outgoing traffic and that serves the purpose. 

    I hope that answers the question.

Children
No Data