
YuChakTinMichael‘sGIACGCFWProjectAssignment
Page 104
n DISALLOWAny<IN&OUT,Any >Any
Anotherinterfacewhichrequiresfilterstobesetupistheinterfaceattachedto
RAS_Net,whichis192.168.22.1:
n RAS_Net(192.168.22.0)< IN&OUT,Any >Internal_Servers(192.168.18.0)
n RAS_Net(192.168.22.0) < IN&OUT,HTTP,HTTPSandDNSQuery >
Public_Services(192.168.8.0)
n DISALLOWAny<IN&OUT,Any >Any
Dependingontheneedsoftheusers,additionaltrafficmaybeallowed.Refertothe
“ProductsPreparation”sectionforafulllistofprotocolscommonlyusedina
Windowsbasednetwork.
Itisalwaysagoodpracticetoexplicitlyadda“dropeverything”ruleasthelast
rule.Thisensuresthatallillegitimaterequestsarelogged.
BasicTesting:
n Fromaninternalclient,accessasharethatbelongstothefileserverinside
Internal_Servers.Theattemptshouldsucceed.
n Fromaninternalclient,accessthedatabaseapplicationserverinside
Critical_Resourcesviatelnet.Theattemptshouldfail.
n Fromaninvalidinternalclient,accesstheintranetserverinsideInternal_Servers
viaHTTP.Theattemptshouldfail.
n Inspectthelogfile.
FurthertestingshouldbeperformedattheAuditstage.
Kommentare zu diesen Handbüchern