
YuChakTinMichael‘sGIACGCFWProjectAssignment
Page 98
ConfiguringtheVisNetic _1Firewall:
Refertot he“ProductsPreparation”section forinformationon VisNeticFirewall.
Refertot he“Products Preparation”section forinformationonWindows2000hardening.
VisNetic_1sitsbetweenthecoreswitchandthefollowingsegments:
n 192.168.18.0(Internal_Servers)
n 192.168.21.0(Critical_Resources)
n 192.168.22.0(RAS_Net)
SecurityPoliciesandOrders:
Thepoliciestobeenforcedhereare:
1. OnlyInternal_Admincanfreelyaccessallsegmentsbehindthisfirewall with
anyprotocol he/shelikes.
2. ExternalpartnersandsupplierscanaccessonlytheCritical_Resourcessegment.
SuchaccessmustoriginatefromCore_NetviaW2K_VPN,usingHTTP and
HTTPS astheprotocols. Theiraccessmustberestrictedbyapplicationlevel
authenticationandauthorization.
3. Internal_ClientsandInternal_DevcanaccessInternal_Serverswithanyprotocol,
althoughtheiraccessmustberestrictedbysystemlevelauthenticationand
authorization.
4. Internal_ClientsandInternal_DevcanaccessCritical_ResourcesonlyviaHTTP
andHTTPS. Theiraccessmustberestrictedbyapplicationlevelauthentication
andauthorization.
5. RASuserswhoconnectviaRAS_NetcanaccesstheInternal_Serverssegment
withanyprotocol,althoughtheiraccessmustberestrictedbysystemlevel
authenticationandauthorization.TheiraccesstoPublic_Servicesissubjectto
filteringatFW2_B2C.
6. Dropandlogeverythingelse.
SincetherulebaseforVisNeticiseffectiveonaperinterfacebasis,orderofrulesis
relevantonlywithinthecontextofindividualinterface.Ruleswithineachinterface
areprocessedsequentially,whichisexactlythesameasthewayrulesareprocessedin
Kommentare zu diesen Handbüchern