SunScreen 3.1 Reference Manual

Single Service

You add new network services and edit the filtering activities applied when a service is used in a rule. You add a new single service using the Service dialog box that appears when you select New Single Service from the Add New combo box in the Common Objects panel, shown in FIGURE 5-14.

Figure 5-14 Service Dialog Box for a New Single Service

Graphic

You control the filtering activities by specifying what packet-filtering engine you want to use and the various discriminators and parameters applicable to that filtering engine.

FIGURE 5-15 shows the filter table of the Service dialog box for a new single service.

Figure 5-15 Service Dialog Box for a New Single Service with Expanded Filter Table

Graphic

TABLE 5-15 describes the controls in the Service dialog box for a single service.

Table 5-15 Controls for Service Dialog Box for Single Service

Control 

Description 

Configuration Information 

Name 

Specifies the name of the service object. 

Description  

(Optional) Provides a brief description about the service object. 

Screen 

(Optional) Restricts the service so that it applies to the selected Screen only. The default (All) means that all Screens recognize this object unless an object exists that has been specifically defined for a particular Screen and has the same name as the Screen for which it is defined.

Filter Table Information 

Filter Table 

Display the parameters for the single services. 

  1. The Add Filter button Adds a row to the filter table so that you can define additional forward filters for the service.

  2. The Add Port button adds ports for use by the forward filter. This field becomes active when you click the port field of the filter table.

  3. The Delete button the highlighted row in the table. You click a row in the table to highlight it.

Filter 

Identifies the state engine. 

Port 

Identifies the port number, program number, or type used by the forward filter. 

Broadcast 

Determines whether the rules in which the service is used allows communication to broadcast or multicast addresses. If you want the service to work for nonbroadcast addresses, you must enter a separate table entries for broadcast and nonbroadcast entries 

Parameters 

Overrides the default values the selected packet-filter state engine. Each state engine has a set of parameters; refer to Appendix C, Services and State Engines for default parameters values and their meaning.

Reverse 

Determines whether the filter applies to packets originating from the host in the To address of a rule and going to the From address of a rule.  

OK Button 

Stores the new or changed information and makes the Save Changes command button active. 

Cancel Button 

Cancels any new or changed information. 

Help Button 

Displays the page of online help for this common object.