Services are a collection of rules or a set of instructions to permit or deny a particular type of traffic through the Firewall, for example, a telnet session. Services figure prominently when defining connections. They specify the type of traffic that can or cannot take place between network objects. The IBM Firewall comes preloaded with a default set of services. You can add to services by using the rule templates to create new rules.
The figure below illustrates how services are composed of rule templates and how they can become part of a connection configuration.
![]() |
Controlling Traffic Through the Firewall |
![]() |
Examples of Services: Proxy Telnet |
![]() |
Examples of Services: Routed Telnet |
![]() |
Examples of Services: Proxy HTTP |
Note: There can be more than one instance of the same rule added to this list. This is because it is possible that an administrator would want to use the same rule template twice, and assign a different value for the "Flow" field. Use caution when selecting rule templates so that you do not select the same instance of a template more times than what you intended.
![]() | Left to Right indicates that the Source and Destination of the Connection will get written directly to the rule as it is written into the Rule Base File. |
![]() | Right to Left indicates that the Source and Destination of the Connection will be reversed when it is written to the Rule Base File. |
The default Security Agreement is "Host Only" which will not permit the Enterprise Firewall Manager to update any of the configuration files for this Managed Firewall.
Note that the Recipient firewall must have "Host Only" selected for its Security Agreement. When the recipient firewall is cloned, the source's assigned Security Agreement will be assigned to the recipient.
Note that whether a service is activated or deactivated depends on the value of the "Time Control Action" field.
Note that whether a service is activated or deactivated depends on the value of the "Time Control Action" field.
Choose "Deactivate Service During Specified Times" if you want this service to be deactivated during the specified times. This service will be activated during the times outside of those specified.
Click "Select" and choose from the list of rules available. You can select more than one rule.
Note: There can be more than one instance of the same rule added to this list. This is because it is possible that an administrator would want to use the same rule template twice, and assign a different value for the "Flow" field. Use caution when selecting rule templates so that you do not select the same instance of a template more times than what you intended.
![]() | Left to Right indicates that the Source and Destination of the Connection will get written directly to the rule as it is written into the Rule Base File. |
![]() | Right to Left indicates that the Source and Destination of the Connection will be reversed when it is written to the Rule Base File. |
![]() | Left to Right indicates that the Source and Destination of the Connection will get written directly to the rule as it is written into the Rule Base File. |
![]() | Right to Left indicates that the Source and Destination of the Connection will be reversed when it is written to the Rule Base File. |
![]() | Left to Right indicates that the Source and Destination of the Connection will get written directly to the rule as it is written into the Rule Base File. |
![]() | Right to Left indicates that the Source and Destination of the Connection will be reversed when it is written to the Rule Base File. |
Note: Anytime you click on a checkbox that pertains to a Predefined Service, and you click on "OK", you must activate these changes via the Connection Activation window. You do not need to activate after changing either of the Transparent Proxy checkboxes as these two do not pertain to Predefined Services.
![]() |
Using the Configuration Client to Define a Security Policy |
Warning: Use of this Service can open your Firewall up to security exposures. Use this service with extreme caution.
![]() | Create new |
![]() | Carrier |
![]() | Create new modem |
![]() | Modem |