
Web Filtering
X Family LSM User’s Guide V 2.5.1 85
Configure a Virtual Server and Provide One-to-One NAT
STEP 1
From the LSM menu, select Firewall > Virtual Servers.
STEP 2
On the Virtual Servers page, To add a new virtual server, click Create. To edit an existing one,
click the Edit icon for that server.
STEP 3
On the Create/Edit Virtual Server page, select the Service that will run on this virtual server.
STEP 4
In the Local IP Address field, enter the IP address of the server on the LAN to which you
want traffic redirected.
For one-to-one NAT, this address is the LAN client address.
STEP 5
For the Public IP Address, either:
•Select Use External interface IP address.
•Select IP Address. Then, type a public IP Address that is different from the X family device
public WAN IP Address.
This option can only be used if you have been provided with multiple IP addresses. You
must select this option for one-to-one NAT.
STEP 6
If you want a default port number used by the service to be translated to a different port num-
ber by the X family device, check Enable PAT and enter the port number you want in the
Local Port field.
STEP 7
Click Create.
Click Cancel to return to the FIREWALL - Virtual Servers page without saving the changes.
Web Filtering
The options on the Web Filtering menu in the LSM enable you to view and change configuration for
web filtering (sometimes known as content filtering). Web filtering allows you to control access to Web
sites from the X family device. The device supports both custom filtering and filtering using the Web
Filter Service.
• Custom filtering enables you to permit or block access to different Web sites based on their URLs,
domain names, IP addresses, pattern matching, or keyword matching. No content categorization is
Note To provide one-to-one NAT to a LAN client, select ALL from the
Service drop-down list.
Note The Enable PAT checkbox and the Local Port field are disabled if
you have selected ALL from the Service drop-down list.
Note Virtual Server traffic is subject to firewall rules. You must set up a firewall
rule to allow the traffic for the desired services through the firewall. To allow
incoming traffic, use the IP address, or the zone containing the IP address, of the
LAN device as the destination address of the firewall rule.
Comentarios a estos manuales