TMS zl Module Planning and Implementation Guide 2009-08

Table Of Contents
Page 79
From our client PC where we performed the pings, we can bring up a web browser and
test our access policy with a connection to the web server on zone6 (IP Address
172.16.05.50) - our web server works!
In certain circumstances, the firewall administrator may not know all the protocols and
ports used by an application. A useful access policy to help diagnose any problems you
may have is to put a “Deny Traffic” as the last policy from Zone5 to Zone6 and enable
logging. This will result in a log message anytime this access policy is triggered.