
YuChakTinMichael‘sGIACGCFWProjectAssignment
Page 127
PPTP inputpacketfiltersareconfiguredontheadapterthatisonthesideof the
Internet(192.168.6.2).
Thisinterface’sInputFiltersshouldbeconfiguredsothat thefilteractionissetto
Dropallpacketsexceptthosethatmeetthecriteriabelow:
n DestinationIPaddressoftheVPNserver'sInternetinterface(192.168.6.2),
subnetmaskof255.255.255.255,andTCPdestinationportof1723.Thisallows
PPTPtunnelmaintenancetrafficfromthePPTPclientstothePPTPserver.
n DestinationIP addressoftheVPNserver'sInternetinterface(192.168.6.2),
subnetmaskof255.255.255.255,andIPProtocolIDof47.Thisfilterallows
PPTPtunneleddatafromthePPTPclientstothePPTPserver.
Donotuse“TCP[established]”astheporttype.ThisfilterisrequiredonlyiftheVPN
serverisactingasaVPNclient(acallingrouter)inaroutertorouterVPNconnection
inwhichtrafficisacceptedonlyiftheVPNserverinitiatedtheTCPconnection.
Kommentare zu diesen Handbüchern