SunScreen 3.1 Reference Manual
    
Numbers and Symbols
 
 5-tuple ( Index Term Link )
    
A
 
 access control ( Index Term Link )
  defining rules ( Index Term Link )
  overview ( Index Term Link )
  packet filtering rules ( Index Term Link )
 
 access level see administrative access level ( Index Term Link )
 
 action
  ALLOW ( Index Term Link )
  DENY ( Index Term Link )
  ENCRYPT ( Index Term Link )
  SECURE ( Index Term Link )
 
 address ( Index Term Link )
  administration ( Index Term Link )
  group ( Index Term Link )
  individual ( Index Term Link )
  IP ( Index Term Link )
  range ( Index Term Link )
 
 address group, dialog box ( Index Term Link )
 
 address objects, multiple Screens ( Index Term Link )
 
 address range, dialog box ( Index Term Link )
 
 ADMIN interface, SunScreen Lite ( Index Term Link )
 
 administration
  address ( Index Term Link )
  certificate ( Index Term Link )
  interfaces ( Index Term Link )
 
 administration graphical user interface. See administration GUI ( Index Term Link )
 
 administration-group, certificate ( Index Term Link )
 
 administration GUI
  administrative access rules ( Index Term Link )
  browser support ( Index Term Link )
  command-line user interface ( Index Term Link ) ( Index Term Link )
  defining VPN gateways ( Index Term Link ) ( Index Term Link )
  documentation button ( Index Term Link ) ( Index Term Link )
  elements ( Index Term Link )
  end-system SKIP ( Index Term Link )
  gateways ( Index Term Link )
  graphical user interface ( Index Term Link )
  Help button ( Index Term Link )
  Information page ( Index Term Link )
  instructions ( Index Term Link )
  interoperability with command line ( Index Term Link )
  local administration ( Index Term Link )
  localhost example ( Index Term Link )
  Login page ( Index Term Link )
  NAT ( Index Term Link )
  NAT rule mapping ( Index Term Link )
  navigation bar ( Index Term Link )
  navigation buttons ( Index Term Link )
  overview ( Index Term Link )
  packet-filtering rules ( Index Term Link )
  Policies List page ( Index Term Link )
  proxies ( Index Term Link )
  reference ( Index Term Link )
  remote administration ( Index Term Link )
  Save As button
   Edit(RO) button ( Index Term Link )
  starting ( Index Term Link )
  version number ( Index Term Link )
  VPN ( Index Term Link )
 
 Administration Station ( Index Term Link )
  components ( Index Term Link ) ( Index Term Link )
  description of ( Index Term Link )
  remote administration ( Index Term Link ) ( Index Term Link ) ( Index Term Link )
 
 administrative access level ( Index Term Link )
 
 administrative access rule
  local ( Index Term Link )
  Policy Rules page ( Index Term Link )
 
 administrative access rules ( Index Term Link )
  remote ( Index Term Link )
 
 administrative user ( Index Term Link )
  authentication ( Index Term Link )
  dialog box ( Index Term Link )
 
 ALLOW action ( Index Term Link )
  controls ( Index Term Link )
 
 associate MKID, dialog box ( Index Term Link )
 
 authentication
  external users ( Index Term Link )
  internal users ( Index Term Link )
  overview ( Index Term Link )
 
 authentication events ( Index Term Link )
 
 authorized user ( Index Term Link ) ( Index Term Link )
  authentication ( Index Term Link ) ( Index Term Link )
  authentication processing logic ( Index Term Link )
  creating ( Index Term Link )
  defining object ( Index Term Link )
  dialog box ( Index Term Link )
  example
   create object ( Index Term Link )
   create object defining SunScreen ( Index Term Link )
   create simple-text object ( Index Term Link )
   display existing object ( Index Term Link )
   display object names ( Index Term Link )
   display objects ( Index Term Link )
  RADIUS details ( Index Term Link )
    
B
 
 backwards compatibility installation ( Index Term Link )
 
 BROADCAST ( Index Term Link )
 
 broadcast traffic ( Index Term Link )
  addbroadcast ( Index Term Link )
  new service ( Index Term Link )
 
 browser
  back, forward, and reload buttons ( Index Term Link )
  HotJava ( Index Term Link )
  log ( Index Term Link )
  Netscape Navigator ( Index Term Link )
    
C
 
 CA issued note ( Index Term Link )
 
 centralized management ( Index Term Link )
  certificate for Screen ( Index Term Link )
  common objects for ( Index Term Link )
  screen object ( Index Term Link )
  screen objects
   screen objects ( Index Term Link )
 
 centralized management group
  concepts ( Index Term Link )
  logs ( Index Term Link )
  primary Screen ( Index Term Link )
  secondary Screens ( Index Term Link )
  setting rules ( Index Term Link )
  SunScreen Lite ( Index Term Link )
 
 certificate
  administration ( Index Term Link )
  administration-group ( Index Term Link )
  associate MKID ( Index Term Link ) ( Index Term Link )
  dialog box ( Index Term Link )
  generating Screen ( Index Term Link )
  group ( Index Term Link )
  issued ( Index Term Link )
  local ( Index Term Link )
  screen object ( Index Term Link )
 
 ciphertext message, proxies ( Index Term Link )
 
 command buttons, Policy Rules page ( Index Term Link )
 
 command-line user interface
  accessing Screen ( Index Term Link )
  administration GUI ( Index Term Link ) ( Index Term Link )
  configuration editor ( Index Term Link )
  reference ( Index Term Link )
 
 commands
  configuration editor ( Index Term Link )
  SunScreen SKIP commands ( Index Term Link )
  UNIX ( Index Term Link )
  unsupported ( Index Term Link )
 
 common objects ( Index Term Link )
  address ( Index Term Link )
  administrative user ( Index Term Link ) ( Index Term Link )
  associate MKID certificate ( Index Term Link )
  authorized user ( Index Term Link ) ( Index Term Link )
  automatically saved ( Index Term Link ) ( Index Term Link ) ( Index Term Link )
  certificate ( Index Term Link )
  components ( Index Term Link )
  data objects ( Index Term Link )
  database ( Index Term Link )
  interface ( Index Term Link )
  jar hash ( Index Term Link )
  jar signature ( Index Term Link )
  multiple Screens ( Index Term Link )
  policy rules ( Index Term Link )
  proxy user ( Index Term Link ) ( Index Term Link )
  screen object ( Index Term Link ) ( Index Term Link )
  service ( Index Term Link )
  time ( Index Term Link )
 
 compatibility
  SKIP ( Index Term Link )
  SunScreen ( Index Term Link )
 
 components
  Administration Station ( Index Term Link ) ( Index Term Link ) ( Index Term Link )
  Screen ( Index Term Link ) ( Index Term Link ) ( Index Term Link )
 
 configuration
  common objects ( Index Term Link )
  security policy ( Index Term Link )
 
 configuration editor
  create controlling objects ( Index Term Link )
  data model ( Index Term Link )
  object types ( Index Term Link )
 
 controlling objects, creating ( Index Term Link )
 
 controls, Policies List page ( Index Term Link )
 
 CoolTalk service ( Index Term Link )
 
 creating, screen objects ( Index Term Link )
 
 cryptography
  authentication ( Index Term Link )
  network layer note ( Index Term Link )
  privacy ( Index Term Link )
  public-key ( Index Term Link ) ( Index Term Link )
  shared-key ( Index Term Link ) ( Index Term Link )
    
D
 
 data model, configuration editor ( Index Term Link )
 
 data object, common objects ( Index Term Link )
 
 database, common objects ( Index Term Link )
 
 decrypting packets ( Index Term Link ) ( Index Term Link )
 
 decryption, function details ( Index Term Link )
 
 defining the name of ( Index Term Link )
 
 definition dialog box ( Index Term Link )
  interface ( Index Term Link )
  NAT ( Index Term Link )
  VPN ( Index Term Link )
 
 DENY action ( Index Term Link )
  controls ( Index Term Link )
 
 description ( Index Term Link )
 
 detail ( Index Term Link )
 
 dialog box ( Index Term Link )
  address group ( Index Term Link )
  address range ( Index Term Link )
  administrative user ( Index Term Link )
  associate MKID ( Index Term Link )
  certificate ( Index Term Link )
  dialog box
   screen object ( Index Term Link )
  host address ( Index Term Link )
  Jar hash ( Index Term Link )
  Jar signature ( Index Term Link )
  local administrative access rules ( Index Term Link )
  policy rule index ( Index Term Link )
  proxy user ( Index Term Link )
  remote administrative access rules ( Index Term Link )
  screen object Primary/Secondary tab ( Index Term Link )
  screen object SNMP tab ( Index Term Link )
  service group ( Index Term Link )
  single service ( Index Term Link )
  time ( Index Term Link )
 
 discriminator ( Index Term Link )
  port ( Index Term Link )
  RPC number ( Index Term Link )
  type ( Index Term Link )
 
 dns service ( Index Term Link )
 
 dns state engine ( Index Term Link )
 
 documentation ( Index Term Link )
  location of HTML files ( Index Term Link )
  location of PDF files ( Index Term Link )
 
 documentation HTML files, location of ( Index Term Link )
 
 documentation PDF files, location of ( Index Term Link )
 
 dynamic packet filtering
  details ( Index Term Link )
  function details ( Index Term Link )
    
E
 
 Edit(RO) button ( Index Term Link )
 
 editing ( Index Term Link )
  screen object ( Index Term Link )
  screen objects ( Index Term Link )
 
 editing a screen object
  Miscellaneous tab ( Index Term Link )
  Primary/Secondary tab ( Index Term Link )
 
 editing a Screen object, SNMP tab ( Index Term Link )
 
 elements, administration GUI ( Index Term Link )
 
 ENCRYPT action ( Index Term Link )
  controls ( Index Term Link )
 
 encrypting packets ( Index Term Link ) ( Index Term Link )
 
 encryption ( Index Term Link ) ( Index Term Link )
  function details ( Index Term Link )
  overview ( Index Term Link )
  proxies ( Index Term Link )
  public-key cryptography ( Index Term Link ) ( Index Term Link )
  shared-key cryptography ( Index Term Link ) ( Index Term Link )
  SKIP ( Index Term Link )
  SunScreen Lite ( Index Term Link )
 
 error messages ( Index Term Link ) ( Index Term Link )
  logged packet reasons ( Index Term Link ) ( Index Term Link )
  ssadm activate ( Index Term Link )
  ssadm edit ( Index Term Link ) ( Index Term Link ) ( Index Term Link )
  ssadm lock ( Index Term Link ) ( Index Term Link )
 
 event logging, function details ( Index Term Link )
 
 external users, authentication of ( Index Term Link )
    
F
 
 failover protection, HA ( Index Term Link )
 
 feature
  centralized management group ( Index Term Link )
  HA ( Index Term Link ) ( Index Term Link )
  NAT ( Index Term Link ) ( Index Term Link ) ( Index Term Link )
 
 FTP proxy
  anonymous FTP ( Index Term Link )
  controlling site access ( Index Term Link )
  destination address ( Index Term Link )
  example
   display variable ( Index Term Link )
   primary Screen ( Index Term Link )
  functions ( Index Term Link )
  global version ( Index Term Link )
  limiting access to ftp commands ( Index Term Link )
  source address ( Index Term Link )
 
 ftp service ( Index Term Link )
 
 ftp state engine ( Index Term Link ) ( Index Term Link )
  PASV mode ( Index Term Link )
 
 function, dynamic packet filtering ( Index Term Link )
 
 functions, dynamic packet filtering ( Index Term Link )
    
G
 
 global log limiter ( Index Term Link )
 
 graphical-user interface ( Index Term Link )
 
 graphical user interfaces
  administration GUI ( Index Term Link )
  installation wizard ( Index Term Link ) ( Index Term Link )
  skiptool GUI ( Index Term Link )
  SunScreen SKIP ( Index Term Link )
    
H
 
 HA
  active Screen ( Index Term Link )
  automatic disconnection ( Index Term Link )
  certificate for Screen ( Index Term Link )
  definition of ( Index Term Link )
  event log ( Index Term Link )
  failover protection ( Index Term Link )
  failure of primary Screen ( Index Term Link )
  function details ( Index Term Link ) ( Index Term Link )
  interface ( Index Term Link )
  limitations ( Index Term Link ) ( Index Term Link )
  overview ( Index Term Link )
  passive Screens ( Index Term Link ) ( Index Term Link )
  reinstate Screen ( Index Term Link )
  screen object ( Index Term Link )
  Solaris 7 for the Intel Platform limitations ( Index Term Link )
  Solaris 7 limitations ( Index Term Link )
  Solaris settings ( Index Term Link )
  state information limitations ( Index Term Link )
  SunScreen Lite ( Index Term Link )
 
 HA cluster
  communicating withftp andtelnet to members of ( Index Term Link )
  communication between members of ( Index Term Link )
  communication in ( Index Term Link )
  configuring ( Index Term Link )
  disrupted connections ( Index Term Link )
  failover ( Index Term Link )
  forcing failover ( Index Term Link )
  function details ( Index Term Link ) ( Index Term Link )
  hubs necessary for ( Index Term Link )
  lost connections ( Index Term Link )
  naming Screen ( Index Term Link )
  network interfaces ( Index Term Link )
  primary Screen ( Index Term Link )
  secondary Screen ( Index Term Link )
  setting up ( Index Term Link )
 
 HA interface, SunScreen Lite ( Index Term Link )
 
 hardening OS
  optional ( Index Term Link )
  stealth mode ( Index Term Link )
 
 help
  documentation ( Index Term Link )
  man pages ( Index Term Link )
  online ( Index Term Link )
 
 Help button ( Index Term Link )
 
 high availability. See HA ( Index Term Link )
 
 host address box, dialog box ( Index Term Link )
 
 hostname
  Screen name ( Index Term Link )
  uname -n command ( Index Term Link )
 
 HotJava browser ( Index Term Link )
 
 HTTP proxy
  defining source address ( Index Term Link )
  example
   display variable ( Index Term Link )
  filtering content ( Index Term Link )
  filtering Java applets ( Index Term Link )
  filtering restrictions ( Index Term Link )
  functions ( Index Term Link )
  limitations ( Index Term Link )
  NAT implementation ( Index Term Link )
  operation ( Index Term Link )
  prevent access ( Index Term Link )
  restrict Web content ( Index Term Link )
  SSL support ( Index Term Link )
  useful in implementing NAT ( Index Term Link )
  using Java ( Index Term Link )
    
I
 
 ICMP messages ( Index Term Link )
 
 ICMP packets ( Index Term Link )
 
 icmp service ( Index Term Link )
 
 icmp state engine ( Index Term Link ) ( Index Term Link )
 
 individual IP addresses
  address groups ( Index Term Link )
  address ranges ( Index Term Link )
  function details ( Index Term Link )
  modifying address note ( Index Term Link )
 
 individual servers, SunScreen Lite ( Index Term Link )
 
 Information page ( Index Term Link )
 
 installation ( Index Term Link )
  requirements ( Index Term Link )
 
 interface ( Index Term Link ) ( Index Term Link )
  routing ( Index Term Link )
  routing mode ( Index Term Link )
  stealth mode ( Index Term Link )
 
 interface objects, single Screen ( Index Term Link )
 
 interfaces
  administration ( Index Term Link )
  HA ( Index Term Link )
  HA cluster network ( Index Term Link )
  mixed routing and stealth ( Index Term Link )
  modes ( Index Term Link )
  routing ( Index Term Link )
  routing mode ( Index Term Link )
  stealth ( Index Term Link )
  SunScreen Lite ( Index Term Link ) ( Index Term Link )
 
 internal users, authentication of ( Index Term Link )
 
 Internet Explorer ( Index Term Link )
 
 IP address, defining rules ( Index Term Link )
 
 IP addresses ( Index Term Link )
 
 ip all service ( Index Term Link )
 
 ip forward service ( Index Term Link )
 
 ip mobile service ( Index Term Link )
 
 ip tunnel service ( Index Term Link )
 
 ipfwd state engine ( Index Term Link )
 
 ipmobile state engine ( Index Term Link )
 
 iptunnel state engine ( Index Term Link )
 
 issued keys and certificates ( Index Term Link )
    
J
 
 Jar hash, dialog box ( Index Term Link )
 
 Jar hashes, VJM ( Index Term Link )
 
 Jar hashes and signatures, JVM ( Index Term Link )
 
 Jar signature, dialog box ( Index Term Link )
 
 Jar signatures, Jar signatures ( Index Term Link )
 
 Java
  plug-in
   installation instructions ( Index Term Link )
   Solaris ( Index Term Link )
   Windows ( Index Term Link )
  SunScreen 3.1 ( Index Term Link )
 
 Java Virtual Machine, see JVM ( Index Term Link )
 
 JVM ( Index Term Link )
  Jar hashes ( Index Term Link )
  Jar hashes and signatures ( Index Term Link )
    
K
 
 key manager
  SKIP ( Index Term Link )
  SunScreen SKIP ( Index Term Link )
 
 keys, issued ( Index Term Link )
    
L
 
 local, certificate ( Index Term Link )
 
 local administration ( Index Term Link )
  administration GUI ( Index Term Link )
  concepts ( Index Term Link ) ( Index Term Link )
  overview ( Index Term Link )
  routing mode Screen ( Index Term Link )
  routing-mode Screen ( Index Term Link )
  URL ( Index Term Link )
 
 local administrative access rules
  dialog box ( Index Term Link )
  Policy Rules page ( Index Term Link )
 
 log
  administration GUI statistics ( Index Term Link )
  altering size ( Index Term Link )
  automated centrally managed group ( Index Term Link )
  automated management ( Index Term Link )
  automated postprocessing logs ( Index Term Link )
  binary records ( Index Term Link )
  bridging macros ( Index Term Link )
  centralized management global group log size ( Index Term Link )
  centralized management group ( Index Term Link ) ( Index Term Link )
  command-line user interface statistics ( Index Term Link )
  common optional attributes ( Index Term Link )
  configuring events using command-line user interface ( Index Term Link )
  embedded string filters ( Index Term Link )
  examining ( Index Term Link ) ( Index Term Link )
  example ( Index Term Link )
   clear ( Index Term Link )
   clear log ( Index Term Link )
   debugging ( Index Term Link )
   defining specific macro ( Index Term Link )
   display global default ( Index Term Link )
   display global log limiter ( Index Term Link )
   display macro definition ( Index Term Link )
   display Screen definitions ( Index Term Link )
   display Screen names ( Index Term Link )
   display size specific Screen ( Index Term Link )
   display specific macro definition ( Index Term Link )
   displaying log statistics ( Index Term Link )
   expanding given macro ( Index Term Link )
   expanding log macro ( Index Term Link )
   get_and_clear automatically ( Index Term Link )
   get_and_clear log ( Index Term Link )
   logapp operand ( Index Term Link )
   logsev operand ( Index Term Link )
   processing local file log record ( Index Term Link )
   processing records ( Index Term Link )
   retrieving items from current log ( Index Term Link )
   saving error message ( Index Term Link )
   setting global default ( Index Term Link )
   setting global default (250MB) ( Index Term Link )
   setting size specific Screen ( Index Term Link )
  extended events ( Index Term Link ) ( Index Term Link )
  extended log event enhancements ( Index Term Link )
  extended log events ( Index Term Link ) ( Index Term Link )
  filtering macros ( Index Term Link )
  filtering mechanisms ( Index Term Link )
  filtering Screen logs ( Index Term Link )
  general event type enhancements ( Index Term Link )
  get_and_clear operation ( Index Term Link )
  global default size ( Index Term Link )
  group-Screen installations ( Index Term Link )
  HA ( Index Term Link )
  HA cluster ( Index Term Link )
  installation ( Index Term Link )
  limiters ( Index Term Link )
  list verb ( Index Term Link )
  listing macros ( Index Term Link )
  local macros ( Index Term Link )
  locations ( Index Term Link )
  logdump extensions ( Index Term Link )
  logged network packet enhancements ( Index Term Link )
  logging server ( Index Term Link )
  macro expansion ( Index Term Link )
  macro name and body ( Index Term Link )
  macros ( Index Term Link )
  macros registry ( Index Term Link )
  manual management ( Index Term Link )
  naming macros ( Index Term Link )
  network session ( Index Term Link ) ( Index Term Link )
  network traffic ( Index Term Link )
  packet filtering ( Index Term Link )
  primary Screen log file size ( Index Term Link )
  propagating limiters ( Index Term Link )
  reason why packet logged ( Index Term Link )
  retrieval and clearing ( Index Term Link )
  secondary Screen log file size ( Index Term Link )
  session summary events ( Index Term Link )
 
 Log, set viewing filter ( Index Term Link )
 
 log
  snoop ( Index Term Link )
  specific Screen ( Index Term Link )
  statistics ( Index Term Link )
  traffic size ( Index Term Link )
  using log macros ( Index Term Link )
  variable ( Index Term Link )
  who cleared log ( Index Term Link )
 
 log browsing
  active Screen ( Index Term Link )
  administration GUI ( Index Term Link )
 
 LOG_DETAIL< /primary> ( Index Term Link )
 
 LOG_NONE ( Index Term Link )
 
 log out ( Index Term Link )
 
 LOG_SESSION ( Index Term Link )
 
 LOG_SUMMARY ( Index Term Link )
 
 logged packet reasons ( Index Term Link ) ( Index Term Link )
  why codes ( Index Term Link )
 
 logging ( Index Term Link )
  packet logging
   detail ( Index Term Link )
   none ( Index Term Link )
  sessions ( Index Term Link )
 
 Login page, fields ( Index Term Link )
    
M
 
 MAC-layer bridging ( Index Term Link )
 
 macros, log filtering ( Index Term Link )
 
 Mail Proxy tab
  screen object ( Index Term Link )
  spam ( Index Term Link )
 
 man page, ssadm logdump ( Index Term Link )
 
 man pages
  help ( Index Term Link )
  SKIP ( Index Term Link )
  Solaris ( Index Term Link )
  SunScreen ( Index Term Link )
 
 message transfer agent, see MTA ( Index Term Link )
 
 Miscellaneous tab, editing a screen object ( Index Term Link )
 
 multiple Screen, policy rules for ( Index Term Link )
 
 multiple Screens
  address objects ( Index Term Link )
  common objects ( Index Term Link )
    
N
 
 names, using characters ( Index Term Link )
 
 naming conventions ( Index Term Link )
 
 NAT ( Index Term Link )
  configuration ( Index Term Link )
  definition dialog box ( Index Term Link )
  demilitarized zone ( Index Term Link )
  dynamic ( Index Term Link )
  example mappings ( Index Term Link )
  function details ( Index Term Link )
  mapping collisions ( Index Term Link )
  sequence ( Index Term Link )
  site mappings ( Index Term Link )
  stateful ( Index Term Link )
  static ( Index Term Link )
  SunScreen Lite ( Index Term Link )
 
 Netscape Navigator ( Index Term Link ) ( Index Term Link )
 
 network address translation, ordered translations ( Index Term Link )
 
 network packet traffic ( Index Term Link )
 
 network security policy, setting up ( Index Term Link )
 
 network services, service groups ( Index Term Link )
 
 network topology
  security policy ( Index Term Link ) ( Index Term Link )
 
 new service
  ip ( Index Term Link )
  ip fwd ( Index Term Link )
  ip mobile ( Index Term Link )
  ip tunnel ( Index Term Link )
 
 nfs readonly service ( Index Term Link )
 
 nis state engine ( Index Term Link )
 
 no logging ( Index Term Link )
    
O
 
 object types
  configuration editor ( Index Term Link )
  named ( Index Term Link )
  ordered ( Index Term Link )
 
 online help ( Index Term Link )
 
 ordered rules sequence ( Index Term Link )
 
 overview
  access control ( Index Term Link )
  administration GUI ( Index Term Link )
  authentication ( Index Term Link )
  encryption ( Index Term Link )
  HA ( Index Term Link )
  local administration ( Index Term Link )
  public-key encryption ( Index Term Link )
  remote administration ( Index Term Link )
    
P
 
 packet filtering
  sequence ( Index Term Link )
  set up rules ( Index Term Link )
  state engine ( Index Term Link )
  stateful service rules ( Index Term Link )
 
 packet-filtering rules ( Index Term Link )
  adding a VPN rule ( Index Term Link )
  VPN rules ( Index Term Link )
 
 Packet Filtering tab
  ALLOW action ( Index Term Link )
  DENY action ( Index Term Link )
  ENCRYPT action ( Index Term Link )
  fields on ( Index Term Link )
  Policy Rules page ( Index Term Link )
  SECURE action ( Index Term Link )
 
 packet logging ( Index Term Link ) ( Index Term Link )
 
 packets
  ALLOW rule ( Index Term Link )
  checking size ( Index Term Link )
  concatenated ( Index Term Link )
  creating ( Index Term Link )
  decrypting ( Index Term Link ) ( Index Term Link )
  DENY rule ( Index Term Link )
  encapsulated ( Index Term Link )
  encrypting ( Index Term Link ) ( Index Term Link )
  filtering ( Index Term Link )
  fragmentation ( Index Term Link )
  ICMP ( Index Term Link )
  ICMP screening guidelines ( Index Term Link )
  IP screening guidelines ( Index Term Link )
  logged error messages ( Index Term Link )
  logging ( Index Term Link ) ( Index Term Link )
  passing RIP ( Index Term Link )
  replacing addresses ( Index Term Link )
  restoring original ( Index Term Link )
  transmission ( Index Term Link )
  tunneling ( Index Term Link )
  VPN ( Index Term Link ) ( Index Term Link )
 
 parameters ( Index Term Link )
 
 password ( Index Term Link )
 
 PASV mode (FTP) ( Index Term Link )
 
 patches
  applying ( Index Term Link ) ( Index Term Link )
  required ( Index Term Link ) ( Index Term Link )
  Solaris 2.6 ( Index Term Link ) ( Index Term Link )
  Solaris For the Intel Platform ( Index Term Link )
  SPARC ( Index Term Link ) ( Index Term Link )
  x86 ( Index Term Link )
 
 ping state engine ( Index Term Link )
 
 plaintext message, proxies ( Index Term Link )
 
 pmap_nis state engine ( Index Term Link )
 
 pmap_tcp state engine ( Index Term Link )
 
 pmap_udp state engine ( Index Term Link )
 
 Policies List page ( Index Term Link )
  controls ( Index Term Link )
 
 policy
  new version ( Index Term Link )
  older version ( Index Term Link )
  rules for with multiple Screens ( Index Term Link )
 
 policy rule index, dialog box ( Index Term Link )
 
 policy rules
  function details ( Index Term Link )
  ordered ( Index Term Link )
  rule syntax ( Index Term Link )
 
 Policy Rules page
  administration GUI ( Index Term Link )
  administrative access rules ( Index Term Link )
  command buttons ( Index Term Link )
  error message ( Index Term Link )
  local administrative access rules ( Index Term Link )
  NAT tab ( Index Term Link )
  packet filtering rules ( Index Term Link )
  Packet Filtering tab ( Index Term Link )
  panel tabs ( Index Term Link )
  remote administrative access rules ( Index Term Link )
  rule definition panel ( Index Term Link )
  VPN tab ( Index Term Link )
 
 Policy Rules panel ( Index Term Link )
 
 policy versions ( Index Term Link ) ( Index Term Link )
 
 primary Screen
  centralized management group ( Index Term Link )
  common objects ( Index Term Link )
 
 primary Screen in centralized management, SunScreen Lite ( Index Term Link )
 
 Primary/Secondary tab, editing a Screen object ( Index Term Link )
 
 proxies ( Index Term Link ) ( Index Term Link )
  activate policy ( Index Term Link ) ( Index Term Link )
  ciphertext message ( Index Term Link )
  client software ( Index Term Link ) ( Index Term Link )
  content filtering ( Index Term Link ) ( Index Term Link )
  DNS configuration ( Index Term Link )
  encryption ( Index Term Link )
  establish proxy user authenticity ( Index Term Link )
  event logging ( Index Term Link )
  example
   session illustration ( Index Term Link )
  extend ( Index Term Link )
  FTP connection ( Index Term Link )
  FTP protocol ( Index Term Link ) ( Index Term Link )
  FTP proxies ( Index Term Link ) ( Index Term Link )
  FTP proxy collateral mapping ( Index Term Link )
  how proxies work ( Index Term Link )
  HTTP protocol ( Index Term Link ) ( Index Term Link )
  JAR hashes ( Index Term Link )
  limitations ( Index Term Link )
  locate proxy user authenticity rule ( Index Term Link )
  multithreaded program ( Index Term Link )
  MX records ( Index Term Link )
  plaintext message ( Index Term Link )
  policy rule matching ( Index Term Link )
  protocols ( Index Term Link )
  proxy user anonymous ( Index Term Link )
  regulate ( Index Term Link )
  SecurID PIN server ( Index Term Link )
  Security Dynamics ACE/Server ( Index Term Link )
  server software ( Index Term Link ) ( Index Term Link )
  setting rules ( Index Term Link ) ( Index Term Link )
  SMTP protocol ( Index Term Link ) ( Index Term Link )
  SunScreen Lite ( Index Term Link )
  system configurations ( Index Term Link ) ( Index Term Link )
  TCP ( Index Term Link )
  TCP only in routing mode ( Index Term Link )
  TCP protocol ( Index Term Link )
  Telnet protocol ( Index Term Link ) ( Index Term Link )
  Telnet proxies ( Index Term Link )
  UDP protocol ( Index Term Link )
  user authentication ( Index Term Link ) ( Index Term Link ) ( Index Term Link )
  variables RADIUS client protocol ( Index Term Link )
 
 proxy user
  authentication ( Index Term Link )
  creating object ( Index Term Link )
  defining object ( Index Term Link )
  dialog box ( Index Term Link )
  example
   add GROUP members ( Index Term Link )
   create GROUP object ( Index Term Link )
   create SIMPLE object ( Index Term Link )
   display all names ( Index Term Link )
   display all objects ( Index Term Link )
   display objects ( Index Term Link )
   remove GROUP object ( Index Term Link )
  FTP proxies ( Index Term Link )
  GROUP object ( Index Term Link )
  GROUP objects ( Index Term Link )
  login ( Index Term Link )
  Login page ( Index Term Link )
  object definition ( Index Term Link )
  RADIUS ( Index Term Link )
  RADIUS access to LDAP ( Index Term Link )
  RADIUS LDAP stored in SDS ( Index Term Link )
  SecurID ( Index Term Link )
  SIMPLE null authentication ( Index Term Link )
  SIMPLE object ( Index Term Link )
  SIMPLE objects ( Index Term Link )
  single ( Index Term Link )
  SPECIAL external authentication method ( Index Term Link )
  special objects ( Index Term Link )
  Telnet proxies ( Index Term Link )
 
 public-key cryptography ( Index Term Link ) ( Index Term Link )
 
 public-key encryption, overview ( Index Term Link )
    
R
 
 RADIUS
  example
   create address objects ( Index Term Link )
   create node secret ( Index Term Link )
   create rule ( Index Term Link )
   create variables ( Index Term Link )
  multiple-Screen installations ( Index Term Link )
  other protocol items ( Index Term Link )
  prefigured parameters ( Index Term Link )
  requestor ( Index Term Link )
  response time ( Index Term Link )
  server port ( Index Term Link )
  testing ( Index Term Link ) ( Index Term Link )
  testing by SDS ( Index Term Link )
  testing by SecurID ( Index Term Link )
  typical configuration ( Index Term Link )
  UDP datagrams ( Index Term Link )
  user authentication details ( Index Term Link )
  variables ( Index Term Link ) ( Index Term Link )
 
 RealAudio ( Index Term Link )
 
 realaudio service ( Index Term Link ) ( Index Term Link )
 
 realaudio state engine ( Index Term Link )
 
 remote-access server ( Index Term Link )
 
 remote administration
  administration GUI ( Index Term Link )
  Administration Station ( Index Term Link ) ( Index Term Link ) ( Index Term Link )
  concepts ( Index Term Link ) ( Index Term Link ) ( Index Term Link )
  overview ( Index Term Link )
  Screen ( Index Term Link ) ( Index Term Link ) ( Index Term Link )
  SunScreen Lite ( Index Term Link )
  URL ( Index Term Link )
 
 remote administrative access rules
  dialog box ( Index Term Link )
  Policy Rules page ( Index Term Link )
 
 remote shell (rsh) ( Index Term Link )
 
 requirements
  hardware ( Index Term Link )
  installation ( Index Term Link )
  patches ( Index Term Link ) ( Index Term Link )
  software ( Index Term Link )
 
 rip service, RIP packets ( Index Term Link )
 
 routing, interfaces ( Index Term Link )
 
 routing and stealth, mixed interfaces ( Index Term Link )
 
 routing information protocol, RIP ( Index Term Link )
 
 routing mode ( Index Term Link )
  capabilities ( Index Term Link )
  HA limitations ( Index Term Link )
  interfaces ( Index Term Link )
  limitations ( Index Term Link )
  remote-access server ( Index Term Link )
  subdividing a network ( Index Term Link )
  traditional firewall ( Index Term Link )
  virtual interface ( Index Term Link )
 
 rpc_tcp state engine ( Index Term Link )
 
 rpc_udp state engine ( Index Term Link )
 
 rsh state engine ( Index Term Link )
  remote shell sessions ( Index Term Link )
 
 rule
  ALLOW ( Index Term Link )
  DENY ( Index Term Link )
    
S
 
 sample network map ( Index Term Link )
 
 Save As button ( Index Term Link )
 
 Screen ( Index Term Link ) ( Index Term Link ) ( Index Term Link )
  active ( Index Term Link )
  active HA Screen ( Index Term Link )
  certificate for in centralized management group ( Index Term Link )
  certificate for in HA cluster ( Index Term Link )
  components ( Index Term Link ) ( Index Term Link )
  configuration objects ( Index Term Link )
  HA limitations ( Index Term Link )
  managing multiple Screens ( Index Term Link )
  multiple management ( Index Term Link )
  passive ( Index Term Link ) ( Index Term Link )
  reinstate ( Index Term Link )
  remote administration ( Index Term Link ) ( Index Term Link ) ( Index Term Link )
  remote headless ( Index Term Link )
 
 Screen certificate generating ( Index Term Link )
 
 Screen description of ( Index Term Link )
 
 Screen name
  definition ( Index Term Link )
  hostname ( Index Term Link )
  IP address ( Index Term Link )
 
 screen object ( Index Term Link ) ( Index Term Link )
  centralized management ( Index Term Link )
  certificate ( Index Term Link )
  creating ( Index Term Link )
  editing ( Index Term Link ) ( Index Term Link )
  HA ( Index Term Link )
  Mail Proxy tab ( Index Term Link )
  Mail Proxy tab dialog box ( Index Term Link )
  Miscellaneous tab ( Index Term Link ) ( Index Term Link )
  Primary/Secondary tab ( Index Term Link )
  Primary/Secondary tab dialog box ( Index Term Link )
  SNMP tab dialog box ( Index Term Link )
 
 screening guidelines
  ICMP packets ( Index Term Link )
  IP packets ( Index Term Link )
 
 secondary Screens
  administration capabilities ( Index Term Link )
  centralized management group ( Index Term Link )
 
 SECURE action ( Index Term Link )
  controls ( Index Term Link )
 
 SecurID
  access paths ( Index Term Link )
  ACE/Agent installation ( Index Term Link )
  example
   token PIN establishment ( Index Term Link )
  example configuration ( Index Term Link )
  example create registry address ( Index Term Link )
  example perform stub client configuration ( Index Term Link )
  stub client ( Index Term Link )
  stub client location ( Index Term Link )
  token PIN ( Index Term Link )
  typical authentication ( Index Term Link )
  UDP and TCP protocols ( Index Term Link )
  use caution in deployment ( Index Term Link )
 
 security considerations ( Index Term Link )
 
 security network, sample network map ( Index Term Link )
 
 security policy
  Initial ( Index Term Link )
  network topology ( Index Term Link ) ( Index Term Link )
  ordered policy rules ( Index Term Link )
  policy objects ( Index Term Link )
  security decisions ( Index Term Link )
  version ( Index Term Link )
 
 service ( Index Term Link )
  group ( Index Term Link )
  single ( Index Term Link )
 
 service group, dialog box ( Index Term Link )
 
 services
  CoolTalk ( Index Term Link )
  creating new ( Index Term Link )
  discriminator ( Index Term Link )
  dns ( Index Term Link )
  ftp ( Index Term Link )
  icmp ( Index Term Link )
  IP address information ( Index Term Link )
  ip all ( Index Term Link )
  ip mobile ( Index Term Link )
  modifying ( Index Term Link )
  network service groups ( Index Term Link )
  nfs readonly ( Index Term Link )
  predefined ( Index Term Link )
  realaudio ( Index Term Link )
  realaudio state engine ( Index Term Link )
  smtp ( Index Term Link )
  sqlnet ( Index Term Link )
  standard ( Index Term Link )
  state engine ( Index Term Link ) ( Index Term Link )
  TCP ( Index Term Link )
  tcp all ( Index Term Link )
 
 services, traceroute ( Index Term Link )
 
 services
  VDOLive ( Index Term Link )
  www ( Index Term Link )
 
 services and service groups
  creating new services ( Index Term Link )
  entries for ports ( Index Term Link )
  modifying services ( Index Term Link )
  standard services ( Index Term Link )
 
 session logging ( Index Term Link )
 
 shared-key cryptography ( Index Term Link ) ( Index Term Link )
 
 single Screen, interface objects ( Index Term Link )
 
 single service, dialog box ( Index Term Link )
 
 SKIP
  compatibility ( Index Term Link )
  encryption ( Index Term Link )
  key manager ( Index Term Link )
  RC2 limitation ( Index Term Link )
  SunScreen Lite ( Index Term Link )
 
 skiptool GUI
  encryption of administration commands ( Index Term Link )
  graphical user interface ( Index Term Link )
 
 small work groups, SunScreen Lite ( Index Term Link )
 
 SMTP proxy
  create rules ( Index Term Link )
  email configuration ( Index Term Link )
  email configuration issues ( Index Term Link )
  example
   add restrictions ( Index Term Link )
   define address group ( Index Term Link ) ( Index Term Link )
   define relay restrictors ( Index Term Link )
   define spam restrictors ( Index Term Link )
   display restrictors ( Index Term Link )
   display spam restrictors ( Index Term Link )
   email rule ( Index Term Link )
   remove restriction ( Index Term Link ) ( Index Term Link )
  functions ( Index Term Link )
  MTA filtering ( Index Term Link )
  operation ( Index Term Link )
  rules ( Index Term Link )
  spam control ( Index Term Link )
 
 smtp service ( Index Term Link )
 
 SNMP, timed status indicator ( Index Term Link )
 
 SNMP tab, editing a screen object ( Index Term Link )
 
 SNMP traps ( Index Term Link )
 
 SNMP traps, supported ( Index Term Link )
 
 snoop ( Index Term Link )
 
 snoop program ( Index Term Link )
 
 snoop program ( Index Term Link ) ( Index Term Link )
 
 Solaris 7, HA limitations ( Index Term Link )
 
 Solaris 2.6
  patch ( Index Term Link ) ( Index Term Link )
 
 Solaris 2.6 for the SPARC and Intel platforms ( Index Term Link )
 
 Solaris 7 for the Intel Platform, HA limitations ( Index Term Link )
 
 Solaris 7 for the SPARC and Intel platforms ( Index Term Link )
 
 Solaris 8 for the SPARC and Intel platforms ( Index Term Link )
 
 spam, Mail Proxy tab ( Index Term Link )
 
 SPARC
  patch ( Index Term Link ) ( Index Term Link )
 
 SQL *Net protocol ( Index Term Link )
 
 sqlnet state engine ( Index Term Link )
 
 ssadm logdump, man page ( Index Term Link )
 
 state engine
  characteristics ( Index Term Link )
  connection management ( Index Term Link )
  discriminator ( Index Term Link )
  discriminator value ( Index Term Link )
  discriminators ( Index Term Link )
  dns ( Index Term Link )
  ftp ( Index Term Link ) ( Index Term Link )
  icmp ( Index Term Link )
  ip ( Index Term Link )
  ipfwd ( Index Term Link )
  ipmobile ( Index Term Link )
  iptunnel ( Index Term Link )
  new service ( Index Term Link )
  nis ( Index Term Link )
  parameters ( Index Term Link )
  ping ( Index Term Link )
  pmap_nis ( Index Term Link )
  pmap_tcp ( Index Term Link )
  pmap_udp ( Index Term Link )
  precedence level ( Index Term Link )
  realaudio ( Index Term Link )
  rpc_tcp ( Index Term Link )
  rpc_udp ( Index Term Link )
  rsh ( Index Term Link )
  services ( Index Term Link )
  tcp ( Index Term Link ) ( Index Term Link )
  tcpall ( Index Term Link )
  udp ( Index Term Link )
  udp_datagram ( Index Term Link )
  udp_stateless ( Index Term Link )
  udpall ( Index Term Link )
 
 state information, HA limitations ( Index Term Link )
 
 statistics, log file ( Index Term Link )
 
 stealth ( Index Term Link )
  interfaces ( Index Term Link )
 
 STEALTH interface, SunScreen Lite ( Index Term Link )
 
 stealth mode
  acts as a bridge ( Index Term Link )
  capabilities ( Index Term Link )
  description ( Index Term Link )
  hardening OS ( Index Term Link )
  interfaces ( Index Term Link ) ( Index Term Link )
  SunScreen Lite ( Index Term Link )
 
 summary
  packet logging
   summary ( Index Term Link )
 
 SunScreen
  command compatibility ( Index Term Link )
  compatibility ( Index Term Link )
  configuration editor ( Index Term Link )
  error messages ( Index Term Link )
  example
   continue adding SecurID rules ( Index Term Link )
  how it works ( Index Term Link )
  migration from SunScreen EFS, Release 2.0 ( Index Term Link )
  migration from SunScreen EFS, Release 3.0 ( Index Term Link )
  migration from SunScreen SPF-200 ( Index Term Link )
  upgrading ( Index Term Link )
 
 SunScreen 3.1, Java ( Index Term Link )
 
 SunScreen and SunScreen Lite
  common features SunScreen Lite and SunScreen
   common features ( Index Term Link )
 
 SunScreen compared with SunScreen Lite ( Index Term Link )
 
 SunScreen EFS 1.1 ( Index Term Link )
 
 SunScreen EFS 3.0
  requisites ( Index Term Link )
  resources ( Index Term Link )
 
 SunScreen Lite ( Index Term Link ) ( Index Term Link ) ( Index Term Link ) ( Index Term Link )
  ADMIN interface ( Index Term Link )
  centralized management group ( Index Term Link )
  encryption ( Index Term Link )
  HA ( Index Term Link )
  HA interface ( Index Term Link )
  individual servers ( Index Term Link )
  interfaces ( Index Term Link )
  limitations ( Index Term Link )
  NAT ( Index Term Link )
  number of interfaces ( Index Term Link )
  primary Screen in a centralized management ( Index Term Link )
  remote administration ( Index Term Link )
  SKIIP ( Index Term Link )
  small work groups ( Index Term Link )
  STEALTH interface ( Index Term Link )
  stealth mode ( Index Term Link )
  time-of-day rules ( Index Term Link ) ( Index Term Link )
 
 SunScreen Lite compared with SunScreen ( Index Term Link )
 
 SunScreen SKIP
  commands ( Index Term Link )
  end-system SKIP ( Index Term Link )
  graphical user interface ( Index Term Link )
  header ( Index Term Link )
  key manager ( Index Term Link )
  limitations note ( Index Term Link )
  log ( Index Term Link )
 
 SunScreen SKIP. See SKIP ( Index Term Link )
    
T
 
 TCP, proxies ( Index Term Link )
 
 tcp all service ( Index Term Link )
 
 TCP service ( Index Term Link )
 
 tcp state engine ( Index Term Link )
 
 tcpall state engine ( Index Term Link )
 
 Telnet proxy
  example
   SunScreen SKIP ( Index Term Link )
  functions ( Index Term Link )
  operation ( Index Term Link )
  other issues ( Index Term Link )
  request user name ( Index Term Link )
  TCP ( Index Term Link )
 
 time, dialog box ( Index Term Link )
 
 time-based rules, function details ( Index Term Link )
 
 time objects ( Index Term Link )
  SunScreen Lite ( Index Term Link )
 
 time-of-day rules, SunScreen Lite ( Index Term Link )
 
 timed status indicator, SNMP ( Index Term Link )
 
 traceroute service ( Index Term Link )
 
 traditional firewall ( Index Term Link )
 
 traffic key, generated ( Index Term Link )
 
 traffic log size ( Index Term Link )
 
 transmission control protocol See TCP. ( Index Term Link )
 
 troubleshooting
  access to console ( Index Term Link )
  gathering information ( Index Term Link )
  printing debug information ( Index Term Link )
  ss_debug_level ( Index Term Link )
 
 Trusted Solaris 7 for the SPARC platform ( Index Term Link )
 
 tunneling
  function details ( Index Term Link ) ( Index Term Link )
  hiding addresses ( Index Term Link )
  packets ( Index Term Link )
    
U
 
 UDP, traceroute service ( Index Term Link )
 
 udp_datagram state engine ( Index Term Link )
 
 udp state engine ( Index Term Link )
 
 udp_stateless state engine ( Index Term Link )
 
 udpall state engine ( Index Term Link )
 
 UNIX commands ( Index Term Link )
 
 unsupported commands ( Index Term Link )
 
 upgrading ( Index Term Link ) ( Index Term Link )
  Solaris support ( Index Term Link )
  Unicode internationalization note ( Index Term Link )
 
 upgrading from SunScreen EFS 1.1 ( Index Term Link )
 
 URL ( Index Term Link )
  remote administration ( Index Term Link )
 
 user, admin ( Index Term Link )
 
 user authentication
  administrative user ( Index Term Link )
  authuser ( Index Term Link )
  function details ( Index Term Link )
  proxy user ( Index Term Link )
 
 users
  external ( Index Term Link )
  internal ( Index Term Link )
    
V
 
 VDOLive service ( Index Term Link )
 
 version
  new policy ( Index Term Link )
  older policy ( Index Term Link )
  policy ( Index Term Link )
  security policy ( Index Term Link )
 
 version number ( Index Term Link )
  administration GUI ( Index Term Link )
  historical ( Index Term Link )
  policy versions ( Index Term Link )
 
 virtual private network. See VPN ( Index Term Link )
 
 VJM, Jar signatures ( Index Term Link )
 
 VPN ( Index Term Link ) ( Index Term Link ) ( Index Term Link )
  adding a rule ( Index Term Link ) ( Index Term Link )
  defining ( Index Term Link )
  definition dialog box ( Index Term Link )
  function details ( Index Term Link ) ( Index Term Link )
  limitations ( Index Term Link )
  overview ( Index Term Link )
  setting up ( Index Term Link ) ( Index Term Link )
  SunScreen Lite ( Index Term Link )
  tunneling data ( Index Term Link )
    
W
 
 why codes, logged packet reasons ( Index Term Link )
 
 www service ( Index Term Link )
    
X
 
 x86
  patch ( Index Term Link ) ( Index Term Link )