
YuChakTinMichael‘sGIACGCFWProjectAssignment
Page 121
SecurityPolicy:
Thesecuritypoliciestobeenforcedhereare:
1. OnlyPPTPconnectionsfromthelegitimateexternalpartners/suppliersare
allowed.
2. Nootherinbound/outboundtraffictypesareallowedthroughthisrouter.That
means,dropandlogeverythingelse.
ConfigureW2K_VPN:
BasedontheunderstandingofourVPNmodel,wecan take thenecessarystepsto
configuresuchaVPN.Thesestepsare:
1.InstallhardwareintheVPNserver
2.ConfigureTCP/IPontheadapters
3.InstalltheRoutingandRemoteAccessservice
4.Enableanyauthenticationmethod
5.Configurestaticroutestoreachintranetlocations
6.IncreasethenumberofPPTPports tosuittheneedofGIAC
7.ConfigurePPTPpacketfilters
W2K_VPNhasthefollowinginterfaces:
n 192.168.6.2(toRouter_Eiconcard)
n 192.168.16.5(tothecoreswitch/Core_Net)
BeforetakingthestepstoconfigurethisVPNserver,itisimportantforustoharden
thissystem.InformationonhowtohardenWindows2000isavailableinAssignment
1.
ConfigureRRAS:
Toconfigure VPNonW2K_VPN,wemustensurethatitactsasaRemoteAccess
Server.Regardingauthentication,weuseWindowsAuthenticationasthe
authenticationprovider.Thecorrespondinguseraccountshavetobesetuponthis
Kommentare zu diesen Handbüchern