Athena NGFW (previously known as Network Secure) provides comprehensive protection for every network perimeter, ensuring the safety of your valuable assets, data, and users from emerging threats.
Sangfor devices allow you to specify access permissions for VPN users so that a specific IP address or branch user on the intranet can access only specific computers and service parameters. You can also use the path selection policy to identify apps based on the 5-tuple defined in the intranet services.
You can configure intranet services to control service access and app identification, which enables security management for VPN tunnels and allows you to specify different path selection policies for different apps, as shown in the following figure.
You can add intranet services by protocol type. On the Intranet Services page, click Add. The Add Intranet Service dialog box appears, as shown in the following figure.
The parameters are described as follows:
Name and Description: Enter a name and a description for the intranet service, which helps manage the intranet service.
Protocol: Select a protocol used by the intranet service.
If you select TCP or UDP, click Add and set the source IP range, source port range, destination IP range, and destination port range, as shown in the following figure.
If you select ICMP, click Add and set the source IP range and destination IP range, as shown in the following figure.