
YuChakTinMichael‘sGIACGCFWProjectAssignment
Page 35
LocalPolicyE nforcement
PoliciesatRouter_Ei concard
1. Performroutingonthethreetrafficstreams:B2B,B2C,INET
2. Packetscominginfromtheinternetareinspectedagainstspoofing.
PoliciesatFW1_B2C
1. Ecommercewebservice– TCPport80(HTTP)and443(SSL)allowedIN
2. Emailservicefortheexternalworld– TCPport25(SMTP)allowedIN
3. DNSservicefortheexternalworld–UDPport53(DNSrequest)allowedIN
4. Dropandlogeverythingelse
PoliciesatFW2_B2C
1,Ecommercewebservice:
n AnytrafficallowedfromInternal_Admin.
n HTTP/HTTPStrafficallowedfromInternal_Dev(DevelopersuseHTTP/HTTPS
basedupdatemethodsuchasFrontpageServerextension).
n HTTP/HTTPStrafficallowedfromInternal_Clients.
n HTTP/HTTPStrafficallowedfromRAS_Net.
2,Externalemailservice:
n AnytrafficallowedfromInternal_Admin.
n SMTPtrafficallowedfromtheinternalemailserverforretrievingandsending
emailstoandfromtheoutsideworld.
3,ExternalDNSservice:
n AnytrafficallowedfromInternal_Admin.
n DNSquerytrafficallowedfromInternal_Dev.
n DNSquerytrafficallowedfromInternal_Clients.
n DNSquerytrafficallowedfromRAS_Net.
Kommentare zu diesen Handbüchern