
YuChakTinMichael‘sGIACGCFWProjectAssignment
Page 85
2,
DonotenabletheSynDefenderGateway option.ItisnotlikelytoseeSynflood
attacksagainstthisfirewallfromtheinsidenetwork.
3,
Configurethefollowingrules:
n Allow AdminaccesstoallserversinPublic_Servicesviaanytraffic.
n AllowStaffaccesstoWWWviaHTTPandHTTPS.
n AllowStaffaccesstoDNSviaDNSquery.
n AllowDevaccesstoWWW viaHTTP andHTTPS.
n AllowDevaccesstoDNS viaDNSquery.
n AllowRAS_UseraccesstoWWWviaHTTPandHTTPS.
n AllowRAS_UseraccesstoDNSviaDNSquery.
n AllowInt_EmailtoreceiveSMTPalertsfromIDS.Weneedthisrulesothatthe
alertscanbeforwardedtotheadministrator’smailbox.Keepinmindthough,
thatwiththisruleinplace,theIDSmustbeabsolutelysecure,oranintrusion
pathtotheinsidenetworkwillcometrue.
n AllowInt_EmailtoinitiateSMTPrequeststoEmail.Weneedthisrulesothat
theinternalemailsystemcaninitializecommunicationwiththeexternalonefor
sendingoutboundemailsandretrievinginboundqueuedemails
4,
Dropandlogeverythingelse. ThisrulemustbetheLASTrule.
Exceptforthelast“Dropeverythingrule”,theorderoftheruleswedefineddoes
notmattergiventhesmallnumberofrulesandtheirnonconflictingnature.
5,
VerifythepolicyviaPolicy – Verify.
6,
Installthepolicy viaPolicy –Install.InstallthepolicyontoSELF.
7,
Performsomebasictesting.
8,
Kommentare zu diesen Handbüchern