Selectively permit or deny any network application or service for one or more groups of users.
User role based application control simplifies the management, improves security and enhances resource utilization.
|
Application Control Based on Employee's Role
|
FMS-Enterprise Gateway offers fine grained control to permit or deny a particular network application to a
group of users. When a user attempts to use a network application or service, FMS checks if the user is
allowed to use the service and permits or denies the request accordingly.
This ability to permit a specific application for certain groups of users while deny to other groups, forms a
powerful mechanism to implement corporate policies about network resource usage. Applications are
controlled based on role of users in the organization by placing similar role users in a single UserClass. Users
can be placed in one of the four user classes: UserClass-1, UserClass-2, UserClass-3 or GuestUserClass.
Applications are allowed or denied based on UserClass of the user. This makes management of application
control an easy task as the administrator needs to only keep track of users' roles rather than individual users
when it comes to deciding if an application is to be permitted or denied for anyone.
FMS comes with most of the standard applications such as Email, HTTP/HTTPS (Web Browsing), FTP,
TFTP, SSH, RSH, POP and many more predefined and ready for use and control. If the administrator is
required to control any new application which is not in the predefined list, s/he can create new entry to
control that application very easily.
In the example below, an organization permits Email for all users but Web Browsing is not allowed for
guest/visiting users.
Please note that this is just an example for illustration purpose only. The administrator can choose
permissions for any application any way s/he wants or to suite corporate policy requirements.