Secure Mobile Access 100 10.2 Administration Guide

Adding User Policies

The Policies page provides policy configuration options.

To add a user access policy

  1. On the Policies page, click Add Policy. The Add Policy window is displayed.

  2. In the Apply Policy To drop-down menu, select whether the policy is applied to an individual host, a range of addresses, all addresses, a network object, a server path, or a URL object. You can also select an individual IPv6 host, a range of IPv6 addresses, or all IPv6 addresses. The Add Policy window changes depending on what type of object you select in the Apply Policy To drop-down menu.

    • IP Address – If your policy applies to a specific host, enter the IP address of the local host machine in the IP Address field. Optionally enter a port range (for example, 4100-4200) or a single port number into the Port Range/Port Number field.
    • IP Network – If your policy applies to a range of addresses, enter the beginning IP address in the IP Network Address field and the subnet mask that defines the IP address range in the Subnet Mask field. Optionally enter a port range (for example, 4100-4200) or a single port number into the Port Range/Port Number field.
    • All Addresses – If your policy applies to all IPv4 addresses, you do not need to enter any IP address information.
    • Network Object – If your policy applies to a predefined network object, select the name of the object from the Network Object drop-down menu. A port or port range can be specified when defining a Network Object.
    • Server Path – If your policy applies to a server path, select one of the following radio buttons in the Resource field:
      • Share (Server path) – When you select this option, type the path into the Server Path field.
      • Network (Domain list)
      • Servers (Computer list)
    • URL Object – If your policy applies to a predefined URL object, type the URL into the URL field.
    • All IPv6 Address – If your policy applies to all IPv6 addresses, you do not need to enter any IP address information.
    • IPv6 Address – If your policy applies to a specific host, enter the IPv6 address of the local host machine in the IPv6 Address field. Optionally enter a port range (for example, 4100-4200) or a single port number into the Port Range/Port Number field.
    • IPv6 Network – If your policy applies to a range of addresses, enter the beginning IPv6 address in the IPv6 Network Address field and the prefix that defines the IPv6 address range in the IPv6 Prefix field. Optionally enter a port range (for example, 4100-4200) or a single port number into the Port Range/Port Number field.
  3. Select the desired Protocol. The available value options in the Protocol field include TCP, UDP, ICMP, and ALL. You can select multiple items among TCP, UDP, and ICMP. However, when ALL is selected, all other options are deselected.
  4. Select the service type in the Service drop-down menu. If you are applying a policy to a network object, the service type is defined in the network object.
  5. Select Allow or Deny from the Status drop-down menu to either permit or deny SMA connections for the specified service and host machine.
  6. Click Accept to update the configuration. After the configuration has been updated, the new policy is displayed in the Edit Local User page.

    The user policies are displayed in the Current User Policies table in the order of priority, from the highest priority policy to the lowest priority policy.

Was This Article Helpful?

Help us to improve our support portal

Techdocs Article Helpful form

Techdocs Article NOT Helpful form

  • Still can't find what you're looking for? Try our knowledge base or ask our community for more help.