Eicon Networks S92 Bedienungsanleitung Seite 133

  • Herunterladen
  • Zu meinen Handbüchern hinzufügen
  • Drucken
  • Seite
    / 209
  • Inhaltsverzeichnis
  • LESEZEICHEN
  • Bewertet. / 5. Basierend auf Kundenbewertungen
Seitenansicht 132
YuChakTinMichael‘sGIACGCFWProjectAssignment
Page 133
ConfiguringtheR ASServer
TheRAS_NetRASserverisa“backdoor”tothenetwork. Itallowsthecompany
staffstoremoteaccessingtheserverresourcesinInternal_Serversaswellastoaccess
thecompanysPublic_Servicesservers.Userswithoutformalaccountsinthedomain
controllerarenotallowedtologinviaRAS.
SecurityPolicy:
1. Onlylegitimateuserswiththevalidcredentialsandfromthevaliddialing
locationsareallowedtologin.
2. Disalloweverythingelse.
RASConfiguration:
ThisRASserverwillbeconfiguredwithapoolof 5modemsand5clientIPaddresses
(thatbelongstotheRAS_Netsubnet)forallocationtothedialinclients. Theseclients
areforcedtotakeandusetheseaddresses.Thecorrespondingfirewallfiltersat
VisNetic_1areconfiguredbasedtomakefilteringdecisionsbasedon theseaddresses.
TomakesurethatthisRASserverdoesnotconstituteasecurityhole,wemust:
n Takestepstoharden this Windows2000system.Refertothe“Products
Preparation”sectionforinformationonhowtoproceed.
n ConfigurethecorrespondingRemoteAccessPoliciesandrequiresstrong
encryptionaswellasstrongauthentication.
n Configureaccountlockoutpolicy torestrictthenumberofloginattempts
allowed.
n Configurethesystemtoacceptincomingcallsonlyfrompredefinednumbers,
andusecallbacksecuritytoensurethatonlythe“trueemployees”andnoone
elsecandialin.
Withremoteaccesspolicies,aconnectionisauthorizedonlyifthesettingsofthe
connectionattempttomatchatleastoneoftheremoteaccesspolicies.Accordingto
Seitenansicht 132
1 2 ... 128 129 130 131 132 133 134 135 136 137 138 ... 208 209

Kommentare zu diesen Handbüchern

Keine Kommentare