diff --git a/src/gui/pixadvanceddialog_q.ui b/src/gui/pixadvanceddialog_q.ui index 7aaa1f24d..a146698df 100644 --- a/src/gui/pixadvanceddialog_q.ui +++ b/src/gui/pixadvanceddialog_q.ui @@ -1,77 +1,122 @@ - + + pixAdvancedDialog_q - - + + true - + 0 0 - 814 - 857 + 655 + 716 - + PIX Firewall Settings - + false - - - - + + + + + + + Qt::Horizontal + + + QSizePolicy::Expanding + + + + 20 + 20 + + + + + + + + OK + + + + + + + Cancel + + + + + + + + + Qt::AlignCenter + + + false + + + + + + 16777215 16777215 - + QTabWidget::North - + QTabWidget::Rounded - - 6 + + 0 - + Qt::ElideNone - + true - - + + Compiler - - + + 20 - - - - + + + + 0 0 - - Output file name (if left blank, the file name is constructed of the firewall object name and extension ".fw") + + Output file name (if left blank, the file name is constructed of the firewall object name and extension ".fw") - + Qt::AlignVCenter - + true - - - + + + 32767 22 @@ -79,12 +124,12 @@ - - - + + + Qt::Horizontal - + 518 20 @@ -92,12 +137,12 @@ - - - + + + Qt::Vertical - + 20 19 @@ -105,102 +150,102 @@ - - - - + + + + 0 0 - + 16777215 16777215 - + Policy Compiler Options - - + + 12 - + 12 - - - - Generate rules assuming the firewall is part of "Any". This makes a difference in rules that use services 'ssh' and 'telnet' since PIX uses special commands to control ssh and telnet access to the firewall machine + + + + Generate rules assuming the firewall is part of "Any". This makes a difference in rules that use services 'ssh' and 'telnet' since PIX uses special commands to control ssh and telnet access to the firewall machine - + Assume firewall is part of 'any' - - - - + + + + 0 0 - + PIX inspects packets with ACLs before it does NAT, while many other firewalls do NAT first and then apply ACLs. Policy compiler can emulate the latter behaviour if this options is turned on. - + Replace NAT'ted objects with their translations in policy rules - - - + + + Normally PIX does not support ouotbound ACL, however policy compiler can emulate them if this option is turned on - + Emulate outbound ACLs - - - + + + Normally PIX does not support ouotbound ACL, however policy compiler can emulate them if this option is turned on - + Generate outbound ACLs - - - + + + If the option is deactivated, compiler treats empty groups as an error and aborts processing the policy. If this option is activated, compiler removes all empty groups from all rule elements. If rule element becomes 'any' after the last empty group has been removed, the whole rule will be ignored. Use this option only if you fully understand how it works! - + Ignore empty groups in rules - - - - In nat rules where network zone object is used in OSrc, ODst and OSrv are 'any' and TSrc defines a global pool for the translation, replace object in OSrc with 'any' to produce PIX command "nat (interface) N 0.0.0.0 0.0.0.0" + + + + In nat rules where network zone object is used in OSrc, ODst and OSrv are 'any' and TSrc defines a global pool for the translation, replace object in OSrc with 'any' to produce PIX command "nat (interface) N 0.0.0.0 0.0.0.0" - + Optimize 'default nat' rules - - - + + + Shadowing happens because a rule is a superset of a subsequent rule and any packets potentially matched by the subsequent rule have already been matched by the prior rule. - + Detect rule shadowing in the policy @@ -208,57 +253,57 @@ - - - - + + + + 0 0 - + 16777215 16777215 - + Verification of NAT rules - - + + 12 - - - + + + Check for duplicate nat rules - - - + + + Check for overlapping global pools - - - + + + Check for overlapping statics - - - - + + + + 0 0 - + Check for overlapping global pools and statics @@ -266,30 +311,30 @@ - - - - - + + + + + Always permit ssh access from the management workstation with this address: - - - - + + + + 0 0 - + 200 0 - + 32767 22 @@ -297,12 +342,12 @@ - - - + + + Qt::Horizontal - + 508 20 @@ -312,15 +357,15 @@ - + - + Qt::Vertical - + QSizePolicy::Expanding - + 20 170 @@ -330,86 +375,86 @@ - - + + Installer - - - - + + + + Built-in installer - - - - + + + + User name used to authenticate to the firewall (leave this empty if you use putty session): - + Qt::AlignLeading|Qt::AlignLeft|Qt::AlignVCenter - + true - - - - + + + + 0 0 - - - + + + Alternative name or address used to communicate with the firewall (also putty session name on Windows) - + Qt::AlignLeading|Qt::AlignLeft|Qt::AlignTop - + true - - - - + + + + 0 0 - - + + - - + + Additional command line parameters for ssh - + false - - - + + + 0 0 - + - 300 + 250 0 @@ -417,29 +462,29 @@ - - + + - - + + Additional command line parameters for scp - + false - - - + + + 0 0 - + - 300 + 250 0 @@ -450,48 +495,48 @@ - - - + + + - - - - - Instead of running generated configuration on the firewall line by line, installer can use scp to copy the file and then "copy file running-config" command to activate it. Ssh v2 and scp servers should be configured on the firewall for this to work. This method works for PIX v7 or later and is much faster than running configuration line by line. + + + + + Instead of running generated configuration on the firewall line by line, installer can use scp to copy the file and then "copy file running-config" command to activate it. Ssh v2 and scp servers should be configured on the firewall for this to work. This method works for PIX v7 or later and is much faster than running configuration line by line. - + true - - - + + + Copy generated configuration file to the firewall using scp - - - - File system on the firewall where configuration file should be saved if it is copied with scp. Examples: "flash:", "disk0:". Should end with a colon ":". If this input field is left blank, installer uses "flash:": + + + + File system on the firewall where configuration file should be saved if it is copied with scp. Examples: "flash:", "disk0:". Should end with a colon ":". If this input field is left blank, installer uses "flash:": - + true - - + + - - - + + + Qt::Horizontal - + 398 20 @@ -502,44 +547,44 @@ - - - + + + External install script - - - + + + - - - + + + 0 0 - - Policy install script (using built-in installer if this field is blank): + + Policy install script : - + Qt::AlignLeading|Qt::AlignLeft|Qt::AlignVCenter - + false - - - + + + 0 0 - + - 300 + 250 0 @@ -547,38 +592,38 @@ - - + + - - - + + + 0 0 - + Command line options for the script: - + Qt::AlignLeading|Qt::AlignLeft|Qt::AlignVCenter - + false - - - + + + 0 0 - + - 300 + 250 0 @@ -586,18 +631,25 @@ + + + + Built-in installer will be used if policy install script field is blank. + + + - + - + Qt::Vertical - + QSizePolicy::Expanding - + 20 20 @@ -607,29 +659,29 @@ - - + + Prolog/Epilog - - - - + + + + - - + + 6 - + - + Qt::Horizontal - + QSizePolicy::Expanding - + 40 20 @@ -637,32 +689,32 @@ - - - + + + Edit - - - + + + The following commands will be added verbatim on top of generated configuration - + Qt::AlignVCenter - + true - - - + + + Qt::ScrollBarAlwaysOn - + Qt::ScrollBarAlwaysOn @@ -670,31 +722,31 @@ - - - + + + - - + + 6 - - - + + + Edit - + - + Qt::Horizontal - + QSizePolicy::Expanding - + 40 20 @@ -702,25 +754,25 @@ - - - + + + Qt::ScrollBarAlwaysOn - + Qt::ScrollBarAlwaysOn - - - + + + The following commands will be added verbatim after generated configuration - + Qt::AlignVCenter - + true @@ -730,20 +782,20 @@ - - + + Timeouts - - + + - + Qt::Horizontal - + QSizePolicy::Expanding - + 40 20 @@ -751,15 +803,15 @@ - + - + Qt::Vertical - + QSizePolicy::Expanding - + 20 30 @@ -767,638 +819,638 @@ - - - + + + QFrame::NoFrame - + QFrame::Sunken - - + + 11 - - - + + + xlate - + Qt::AlignCenter - + false - - - + + + conn - + Qt::AlignCenter - + false - - - + + + udp - + Qt::AlignCenter - + false - - - + + + rpc - + Qt::AlignCenter - + false - - - + + + h323 - + Qt::AlignCenter - + false - - - + + + sip - + Qt::AlignCenter - + false - - - + + + sip&media - + Qt::AlignCenter - + false - + sip_media_hh - - - + + + unauth - + Qt::AlignCenter - + false - - - + + + 0 - + 100 - + 0 - - - + + + 0 - + 100 - + 0 - - - + + + 0 - + 100 - + 0 - - - + + + 0 - + 100 - + 0 - - - + + + 0 - + 100 - + 0 - - - + + + 0 - + 100 - + 0 - - - + + + 0 - + 100 - + 0 - - - + + + 0 - + 100 - + 0 - - - + + + 0 - + 59 - + 0 - - - + + + 0 - + 59 - + 0 - - - + + + 0 - + 59 - + 0 - - - + + + 0 - + 59 - + 0 - - - + + + 0 - + 59 - + 0 - - - + + + 0 - + 59 - + 0 - - - + + + 0 - + 59 - + 0 - - - + + + 0 - + 59 - + 0 - - - + + + 0 - + 59 - + 0 - - - + + + 0 - + 59 - + 0 - - - + + + 0 - + 59 - + 0 - - - + + + 0 - + 59 - + 0 - - - + + + 0 - + 59 - + 0 - - - + + + 0 - + 59 - + 0 - - - + + + 0 - + 59 - + 0 - - - + + + 0 - + 59 - + 0 - - - + + + telnet - + Qt::AlignCenter - + false - - - + + + ssh - + Qt::AlignCenter - + false - - - + + + ss - + Qt::AlignCenter - + false - - - + + + mm - + Qt::AlignCenter - + false - - - + + + hh - + Qt::AlignCenter - + false - - - + + + 0 - + 59 - + 0 - - - + + + 0 - + 59 - + 0 - - - + + + 0 - + 100 - + 0 - - - + + + half-closed - + Qt::AlignCenter - + false - - - + + + 0 - + 59 - + 0 - - - + + + 0 - + 59 - + 0 - - - + + + QFrame::HLine - + QFrame::Sunken - + Qt::Horizontal - - - + + + - - + + 6 - - - + + + Inactivity - + Qt::AlignCenter - + false - - - + + + Absolute - + Qt::AlignCenter - + false - - - + + + - - - + + + @@ -1409,45 +1461,45 @@ - - - + + + Set all to defaults.. - - + + Inspect - - - - + + + + Policy compiler generates 'fixup' commands for PIX v6.1-6.3 and FWSM v2.3. For PIX 7.0 it generates 'class-map' and 'inspect' commands assigned to the 'policy-map' under either default or custom inspection classes. - + Qt::AlignVCenter - + true - + 12 - + - + Qt::Vertical - + QSizePolicy::Fixed - + 20 10 @@ -1455,113 +1507,113 @@ - - - - + + + + 0 0 - + 16777215 16777215 - + QTabWidget::North - + QTabWidget::Triangular - + 1 - + Qt::ElideNone - + true - - + + ctiqbe - - + + 0 - - + + - + skip - + enable - + disable - - - + + + Computer Telephony Interface Quick Buffer Encoding (CTIQBE) protocol inspection module that supports NAT, PAT, and bi-directional NAT. - + Qt::AlignLeading|Qt::AlignLeft|Qt::AlignVCenter - + true - - - + + + port: - + Qt::AlignCenter - + false - + pix_ctiqbe_port - - - + + + 1 - + 65535 - + 2748 - + - + Qt::Horizontal - + QSizePolicy::Expanding - + 80 20 @@ -1571,84 +1623,84 @@ - - + + dns - - + + 0 - - - + + + Based on this maximum-length configured by the user, the DNS fixup checks to see if the DNS packet length is within this limit. Every UDP DNS packet (request/response) undergoes the above check. - + Qt::AlignLeading|Qt::AlignLeft|Qt::AlignVCenter - + true - - - + + + max length: - + Qt::AlignCenter - + false - + pix_dns_max_length - - - + + + 512 - + 65535 - + 65535 - - + + - + skip - + enable - + disable - + - + Qt::Horizontal - + QSizePolicy::Expanding - + 40 20 @@ -1658,55 +1710,55 @@ - - + + esp ike - - + + 0 - - - + + + Enables PAT for Encapsulating Security Payload (ESP), single tunnel. - + Qt::AlignCenter - + true - - + + - + skip - + enable - + disable - + - + Qt::Horizontal - + QSizePolicy::Expanding - + 40 20 @@ -1716,72 +1768,72 @@ - - + + ftp - - + + 0 - - - + + + - - - + + + 1 - + 65535 - + 21 - - - + + + port: - + Qt::AlignCenter - + false - + pix_ftp_port - - - + + + strict: - + Qt::AlignCenter - + false - + - + Qt::Horizontal - + QSizePolicy::Expanding - + 40 20 @@ -1789,125 +1841,125 @@ - - + + - + skip - + enable - + disable - - - + + + Activated support for FTP protocol and allows to change the ftp control connection port number. - + Qt::AlignLeading|Qt::AlignLeft|Qt::AlignVCenter - + true - - + + h323 h225 - - + + 0 - - - + + + Specifies to use H.225, the ITU standard that governs H.225.0 session establishment and packetization, with H.323 - + Qt::AlignLeading|Qt::AlignLeft|Qt::AlignVCenter - + true - - - + + + port: - + Qt::AlignCenter - + false - + pix_ctiqbe_port - - - + + + -- - + Qt::AlignCenter - + false - - - + + + 1 - + 65535 - + 1720 - - - + + + 1 - + 65535 - + 1720 - + - + Qt::Horizontal - + QSizePolicy::Expanding - + 30 20 @@ -1915,20 +1967,20 @@ - - + + - + skip - + enable - + disable @@ -1936,91 +1988,91 @@ - - + + h323 ras - - + + 0 - - - + + + Specifies to use RAS with H.323 to enable dissimilar communication devices to communicate with each other. - + Qt::AlignLeading|Qt::AlignLeft|Qt::AlignVCenter - + true - - - + + + 1 - + 65535 - + 1718 - - - + + + -- - + Qt::AlignCenter - + false - - - + + + port: - + Qt::AlignCenter - + false - + pix_ctiqbe_port - - - + + + 1 - + 65535 - + 1719 - + - + Qt::Horizontal - + QSizePolicy::Expanding - + 40 20 @@ -2028,20 +2080,20 @@ - - + + - + skip - + enable - + disable @@ -2049,91 +2101,91 @@ - - + + http - - + + 0 - - - + + + The default port for HTTP is 80. Use the port option to change the HTTP port, or specify a range of HTTP ports. - + Qt::AlignLeading|Qt::AlignLeft|Qt::AlignVCenter - + true - - - + + + -- - + Qt::AlignCenter - + false - - - + + + port: - + Qt::AlignCenter - + false - + pix_ctiqbe_port - - - + + + 1 - + 65535 - + 80 - - - + + + 1 - + 65535 - + 80 - + - + Qt::Horizontal - + QSizePolicy::Expanding - + 40 20 @@ -2141,20 +2193,20 @@ - - + + - + skip - + enable - + disable @@ -2162,55 +2214,55 @@ - - + + icmp error - - + + 0 - - - + + + Enables NAT of ICMP error messages. This creates translations for intermediate hops based on the static or network address translation configuration on the firewall. - + Qt::AlignLeading|Qt::AlignLeft|Qt::AlignVCenter - + true - - + + - + skip - + enable - + disable - + - + Qt::Horizontal - + QSizePolicy::Expanding - + 40 20 @@ -2220,91 +2272,91 @@ - - + + ils - - + + 0 - - - + + + Provides NAT support for Microsoft NetMeeting, SiteServer, and Active Directory products that use LightWeight Directory Access Protocol (LDAP) to exchange directory information with an for Internet Locator Service (ILS) server. - + Qt::AlignLeading|Qt::AlignLeft|Qt::AlignVCenter - + true - - - + + + 1 - + 65535 - + 389 - - - + + + port: - + Qt::AlignCenter - + false - + pix_ctiqbe_port - - - + + + 1 - + 65535 - + 389 - - - + + + -- - + Qt::AlignCenter - + false - + - + Qt::Horizontal - + QSizePolicy::Expanding - + 40 20 @@ -2312,20 +2364,20 @@ - - + + - + skip - + enable - + disable @@ -2333,110 +2385,110 @@ - - + + mgcp - - + + 0 - - - + + + Enables the Media Gateway Control Protocol (MGCP) fixup. - + Qt::AlignCenter - + true - - - + + + Gateway Port: - + Qt::AlignCenter - + false - + pix_ctiqbe_port - - - + + + Call Agent port: - + Qt::AlignCenter - + false - - - + + + 1 - + 65535 - + 2427 - - - + + + 1 - + 65535 - + 2727 - - + + - + skip - + enable - + disable - + - + Qt::Horizontal - + QSizePolicy::Expanding - + 40 20 @@ -2444,15 +2496,15 @@ - + - + Qt::Horizontal - + QSizePolicy::Expanding - + 160 20 @@ -2462,65 +2514,65 @@ - - + + pptp - - + + 0 - - - + + + Enables Point-to-Point Tunneling Protocol (PPTP) application inspection. - + Qt::AlignLeading|Qt::AlignLeft|Qt::AlignVCenter - + true - - - + + + 1 - + 65535 - + 1723 - - - + + + port: - + Qt::AlignCenter - + false - + pix_ftp_port - + - + Qt::Horizontal - + QSizePolicy::Expanding - + 40 20 @@ -2528,20 +2580,20 @@ - - + + - + skip - + enable - + disable @@ -2549,62 +2601,62 @@ - - + + rsh - - + + 0 - - - + + + Enables inspection of RSH protocol. - + Qt::AlignCenter - + true - - - + + + port: - + Qt::AlignCenter - + false - - - + + + 1 - + 65535 - + 514 - + - + Qt::Horizontal - + QSizePolicy::Expanding - + 40 20 @@ -2612,20 +2664,20 @@ - - + + - + skip - + enable - + disable @@ -2633,65 +2685,65 @@ - - + + rtsp - - + + 0 - - - + + + Lets PIX Firewall pass Real Time Streaming Protocol (RTSP) packets. RTSP is used by RealAudio, RealNetworks, Apple QuickTime 4, RealPlayer, and Cisco IP/TV connections. - + Qt::AlignLeading|Qt::AlignLeft|Qt::AlignVCenter - + true - - - + + + 1 - + 65535 - + 554 - - - + + + port: - + Qt::AlignCenter - + false - + pix_ctiqbe_port - + - + Qt::Horizontal - + QSizePolicy::Expanding - + 40 20 @@ -2699,20 +2751,20 @@ - - + + - + skip - + enable - + disable @@ -2720,91 +2772,91 @@ - - + + sip - - + + 0 - - - + + + Enable or change the port assignment for the Session Initiation Protocol (SIP) for Voice over IP TCP connections. - + Qt::AlignLeading|Qt::AlignLeft|Qt::AlignVCenter - + true - - - + + + 1 - + 65535 - + 5060 - - - + + + 1 - + 65535 - + 5060 - - - + + + port: - + Qt::AlignCenter - + false - + pix_ctiqbe_port - - - + + + -- - + Qt::AlignCenter - + false - + - + Qt::Horizontal - + QSizePolicy::Expanding - + 40 20 @@ -2812,20 +2864,20 @@ - - + + - + skip - + enable - + disable @@ -2833,62 +2885,62 @@ - - + + sip udp - - + + 0 - - - + + + Enable SIP-over-UDP application inspection. - + Qt::AlignCenter - + true - - - + + + 1 - + 65535 - + 5060 - - - + + + port: - + Qt::AlignCenter - + false - + - + Qt::Horizontal - + QSizePolicy::Expanding - + 40 20 @@ -2896,20 +2948,20 @@ - - + + - + skip - + enable - + disable @@ -2917,91 +2969,91 @@ - - + + skinny - - + + 0 - - - + + + Enable SCCP application inspection. SCCP protocol supports IP telephony and can coexist in an H.323 environment. An application layer ensures that all SCCP signaling and media packets can traverse the PIX Firewall and interoperate with H.323 terminals. - + Qt::AlignLeading|Qt::AlignLeft|Qt::AlignVCenter - + true - - - + + + -- - + Qt::AlignCenter - + false - - - + + + 1 - + 65535 - + 2000 - - - + + + 1 - + 65535 - + 2000 - - - + + + port: - + Qt::AlignCenter - + false - + pix_ctiqbe_port - + - + Qt::Horizontal - + QSizePolicy::Expanding - + 40 20 @@ -3009,20 +3061,20 @@ - - + + - + skip - + enable - + disable @@ -3030,91 +3082,91 @@ - - + + smtp - - + + 0 - - - + + + Enables the Mail Guard feature, which only lets mail servers receive the RFC 821, section 4.5.1, commands of HELO, MAIL, RCPT, DATA, RSET, NOOP, and QUIT. All other commands are translated into X's which are rejected by the internal server. - + Qt::AlignCenter - + true - - - + + + port: - + Qt::AlignCenter - + false - + pix_ctiqbe_port - - - + + + -- - + Qt::AlignCenter - + false - - - + + + 1 - + 65535 - + 25 - - - + + + 1 - + 65535 - + 25 - + - + Qt::Horizontal - + QSizePolicy::Expanding - + 40 20 @@ -3122,20 +3174,20 @@ - - + + - + skip - + enable - + disable @@ -3143,91 +3195,91 @@ - - + + sqlnet - - + + 0 - - - + + + Enables support for SQL*Net protocol. - + Qt::AlignCenter - + true - - - + + + 1 - + 65535 - + 1521 - - - + + + port: - + Qt::AlignCenter - + false - + pix_ctiqbe_port - - - + + + -- - + Qt::AlignCenter - + false - - - + + + 1 - + 65535 - + 1521 - + - + Qt::Horizontal - + QSizePolicy::Expanding - + 40 20 @@ -3235,20 +3287,20 @@ - - + + - + skip - + enable - + disable @@ -3256,65 +3308,65 @@ - - + + tftp - - + + 0 - - - + + + Enable TFTP application inspection. - + Qt::AlignCenter - + true - - - + + + 1 - + 65535 - + 69 - - - + + + port: - + Qt::AlignCenter - + false - + pix_ctiqbe_port - + - + Qt::Horizontal - + QSizePolicy::Expanding - + 40 20 @@ -3322,20 +3374,20 @@ - - + + - + skip - + enable - + disable @@ -3345,17 +3397,17 @@ - - + + - + Qt::Horizontal - + QSizePolicy::Expanding - + 40 20 @@ -3364,44 +3416,44 @@ - - + + Enable all protocols - + false - - + + Disable all protocols - + false - - + + Skip all protocols - + false - + Qt::Horizontal - + QSizePolicy::Expanding - + 40 20 @@ -3411,86 +3463,86 @@ - - - + + + 16777215 16777215 - + Qt::ScrollBarAlwaysOn - + Qt::ScrollBarAlwaysOn - - + + Logging - - - - + + + + - - - - + + + + Syslog host (name or IP address): - + Qt::AlignRight|Qt::AlignTrailing|Qt::AlignVCenter - + false - - + + - - - + + + Syslog message queue size (messages): - + Qt::AlignRight|Qt::AlignTrailing|Qt::AlignVCenter - + false - - - + + + 0 - + 10000 - + 0 - + - + Qt::Horizontal - + QSizePolicy::Expanding - + 40 20 @@ -3498,28 +3550,28 @@ - - - + + + syslog facility: - + Qt::AlignRight|Qt::AlignTrailing|Qt::AlignVCenter - + false - - + + - - - + + + Qt::Horizontal - + 345 20 @@ -3527,28 +3579,28 @@ - - - + + + syslog level ('logging trap'): - + Qt::AlignRight|Qt::AlignTrailing|Qt::AlignVCenter - + false - - + + - - - + + + Qt::Horizontal - + 345 20 @@ -3556,38 +3608,38 @@ - - - + + + PIX Firewall Version 6.3 introduces support for EMBLEM format, which is required when using the CiscoWorks Resource Manager Essentials (RME) syslog analyzer. - + Use 'EMBLEM' format for syslog messages - - - + + + Set device id for syslog messages (v6.3 and later): - - - - + + + + use hostname - + - + Qt::Horizontal - + QSizePolicy::Expanding - + 40 20 @@ -3595,22 +3647,22 @@ - - - + + + use address of interface - - + + - - - + + + Qt::Horizontal - + 387 20 @@ -3618,35 +3670,35 @@ - - - + + + use text string - - + + - - - + + + The logging timestamp command requires that the clock command be set. - + Qt::AlignVCenter - + true - - - + + + Enable logging timestamps on syslog file @@ -3654,22 +3706,22 @@ - - - + + + Other logging destinations and levels: - - - - + + + + Internal buffer - - - + + + 0 22 @@ -3677,12 +3729,12 @@ - - - + + + Qt::Horizontal - + 488 20 @@ -3690,16 +3742,16 @@ - - - + + + Console - - - + + + 0 22 @@ -3707,12 +3759,12 @@ - - - + + + Qt::Horizontal - + 488 20 @@ -3723,15 +3775,15 @@ - + - + Qt::Vertical - + QSizePolicy::Expanding - + 20 40 @@ -3741,161 +3793,161 @@ - - + + Script - - - - - + + + + + 0 0 - + - - - + + + - - - + + + 0 0 - + - - + + Clear all access lists then install new ones. This method may interrupt access to the firewall if you manage it remotely via IPSEC tunnel. This is the way access lists were generated in older versions of Firewall Builder for PIX. - + Qt::AlignVCenter - + true - + pix_acl_basic - - + + - - - + + + 0 0 - + - - + + Qt::ClickFocus - + Do not clear access lists and object group, just generate PIX commands for the new ones. Use this option if you have your own policy installation scripts. - + Qt::AlignVCenter - + true - + pix_acl_no_clear - - + + - - - + + + 0 0 - + - - - "Safety net" method: + + + "Safety net" method: First, create temporary access list to permit connections from the management subnet specified below to the firewall and assign it to outside interface. This temporary ACL helps maintain session between management station and the firewall while access lists are reloaded in case connection comes over IPSEC tunnel. Then clear permanent lists, recreate them and assign to interfaces. This method ensures that remote access to the firewall is maintained without interruption at a cost of slightly larger configuration. - + Qt::AlignVCenter - + true - + pix_acl_substitution - - - + + + QFrame::StyledPanel - + QFrame::Sunken - - + + 11 - - - + + + Temporary access list should permit access from this address or subnet (use prefix notation to specify subnet, e.g. 192.0.2.0/24): - + Qt::AlignVCenter - + true - + - + Qt::Horizontal - + QSizePolicy::Expanding - + 110 20 @@ -3903,21 +3955,21 @@ First, create temporary access list to permit connections from the management su - - - - + + + + 0 0 - + 200 0 - + 120 32767 @@ -3925,15 +3977,15 @@ First, create temporary access list to permit connections from the management su - + - + Qt::Horizontal - + QSizePolicy::Expanding - + 120 20 @@ -3947,25 +3999,25 @@ First, create temporary access list to permit connections from the management su - - - + + + - - - - + + + + Compiler can generate PIX configuration without commands that configures interfaces, timeouts and inspectors. These parts of configuration change rarely so it makes no sense to execute the same commands again and again. In addition, runnig the same commands on configuration reload cause errors. Use this option to generate shortened configuration to avoid errors and make update faster. - + true - - - + + + Generate only access-list, access-group, telnet, ssh, nat, global and static commands @@ -3973,54 +4025,54 @@ First, create temporary access list to permit connections from the management su - - - - + + + + 0 0 - + - - + + 12 - - - + + + Insert comments into generated PIX configuration file - + Comment the code - - - + + + Use ACL remarks to relate ACL commands and policy rules in the GUI - + Use ACL remarks - - - + + + Group PIX commands in the script so that similar commands appear next to each other, just like PIX does it when you use 'show config' - + Group similar commands together - - - + + + Use manual ACL commit on FWSM @@ -4028,12 +4080,12 @@ First, create temporary access list to permit connections from the management su - - - + + + Qt::Vertical - + 20 137 @@ -4043,85 +4095,85 @@ First, create temporary access list to permit connections from the management su - - + + PIX Options - - + + 20 - + 20 - + 12 - + 20 - + 20 - - + + QFrame::NoFrame - + QFrame::Plain - - + + 12 - - - + + + Actively reset inbound TCP connections with RST - + - - - + + + Actively reset inbound TCP connections with RST on outside interface - + - - - + + + Force each TCP connection to linger in a shortened TIME&WAIT - + Alt+W - - - + + + Enable the IP Frag Guard feature (deprecated in v6.3 and later). - - - + + + Enable TCP resource control for AAA Authentication Proxy - - - + + + Specify that when an incoming packet does a route lookup, the incoming interface is used to determine which interface the packet should go to, and which is the next hop @@ -4129,103 +4181,103 @@ the packet should go to, and which is the next hop - - - + + + QFrame::HLine - + QFrame::Sunken - + Qt::Horizontal - - - + + + Disable inbound embedded DNS A record fixups - - - + + + Disable outbound DNS A record replies - - - + + + QFrame::HLine - + QFrame::Sunken - + Qt::Horizontal - - - + + + The following parameters are used for all NAT rules: - + Qt::AlignLeading|Qt::AlignLeft|Qt::AlignVCenter - + false - - - + + + maximum number of simultaneous TCP and UDP connections - + Qt::AlignLeading|Qt::AlignLeft|Qt::AlignVCenter - + false - + max_conns - - - + + + 64 16777215 - + Specifies the maximum number of simultaneous TCP and UDP connections for the entire subnet. The default is 0, which means unlimited connections. (Idle connections are closed after the idle timeout specified by the timeout conn command.) - + 0 - + 100000 - + 0 - - - + + + Qt::Horizontal - + 254 20 @@ -4233,66 +4285,66 @@ the packet should go to, and which is the next hop - - - + + + maximum number of embryonic connections per host - + Qt::AlignLeading|Qt::AlignLeft|Qt::AlignVCenter - + false - + emb_limit - - - + + + 64 16777215 - + Specifies the maximum number of embryonic connections per host. An embryonic connection is a connection request that has not finished the necessary handshake between source and destination. Set a small value for slower systems, and a higher value for faster systems. The default is 0, which means unlimited embryonic connections. - + 0 - + 100000 - + 0 - - - + + + (The default for both parameters is 0, which means unlimited number of connections.) - + Qt::AlignLeading|Qt::AlignLeft|Qt::AlignVCenter - + true - + - + Qt::Vertical - + QSizePolicy::Expanding - + 20 20 @@ -4305,27 +4357,27 @@ the packet should go to, and which is the next hop - - + + IPv6 - - + + 20 - - - + + + The order in which ipv4 and ipv6 rules should be generated: - + - + Qt::Horizontal - + 40 20 @@ -4333,26 +4385,26 @@ the packet should go to, and which is the next hop - - + + - + IPv4 before IPv6 - + IPv6 before IPv4 - + - + Qt::Vertical - + 20 40 @@ -4364,53 +4416,9 @@ the packet should go to, and which is the next hop - - - - - - Qt::Horizontal - - - QSizePolicy::Expanding - - - - 20 - 20 - - - - - - - - OK - - - - - - - Cancel - - - - - - - - - Qt::AlignCenter - - - false - - - - + tabWidget outputFileName @@ -4565,11 +4573,11 @@ the packet should go to, and which is the next hop pixAdvancedDialog_q accept() - + 20 20 - + 20 20 @@ -4581,11 +4589,11 @@ the packet should go to, and which is the next hop pixAdvancedDialog_q reject() - + 20 20 - + 20 20 @@ -4597,11 +4605,11 @@ the packet should go to, and which is the next hop pixAdvancedDialog_q editProlog() - + 20 20 - + 20 20 @@ -4613,11 +4621,11 @@ the packet should go to, and which is the next hop pixAdvancedDialog_q editEpilog() - + 20 20 - + 20 20 @@ -4629,11 +4637,11 @@ the packet should go to, and which is the next hop pixAdvancedDialog_q defaultTimeouts() - + 20 20 - + 20 20 @@ -4645,11 +4653,11 @@ the packet should go to, and which is the next hop pixAdvancedDialog_q enableAllFixups() - + 20 20 - + 20 20 @@ -4661,11 +4669,11 @@ the packet should go to, and which is the next hop pixAdvancedDialog_q disableAllFixups() - + 20 20 - + 20 20 @@ -4677,11 +4685,11 @@ the packet should go to, and which is the next hop pixAdvancedDialog_q skipAllFixups() - + 20 20 - + 20 20 @@ -4693,11 +4701,11 @@ the packet should go to, and which is the next hop pixAdvancedDialog_q scriptACLModeChanged() - + 20 20 - + 20 20 @@ -4709,11 +4717,11 @@ the packet should go to, and which is the next hop pixAdvancedDialog_q scriptACLModeChanged() - + 20 20 - + 20 20