
YuChakTinMichael‘sGIACGCFWProjectAssignment
Page 99
FW1.
DefiningtheInterfaces:
VisNetichasitsrulesconfiguredonaperinterfacebasis.So,fortraffictopass
throughitandobtainafeedbackfromtheotherside,configurationmustbemadeon
all theinterfacesinvolved.
VisNetic_1hasthefollowinginterfaces:
n 192.168.16.6(tothecoreswitch/Core_Net)
n 192.168.18.1(toInternal_Servers)
n 192.168.21.1(toCritical_Resources)
n 192.168.22.1(toRAS_Net)
TheConfigurationWizardcanbeusedtoputtheidleinterfacestoan “unused”state.
Wecannotrelysolelyonthefirewalltoprovideallsortsof protections!!!
IhaveallowedInternal_Clients,Internal_DevandRAS_Netusersaccessto
Internal_Serverswithwhateverprotocolstheylike.Therationalesare:
n TherearesomanydifferenttypesofservicespossibleinaMicrosoftWindows
basedNetwork,thatmanyoftheseservicesrelyonmultiple protocolsthatare
mutuallydependent.Blockingtheseprotocolsonebyoneispossible,butis
imposingheavyadministrativeburden,especiallywhennewapplications
usingnewprotocolsareregularlyintroduced(given thepaceoftechnological
advance,thisishighlylikelypossible).
n DifferentusersintheInternal_Clientsgrouprequiresaccesstodifferent
services.Blockingatthefirewallcanbeinflexibleandtroublesome.
Theref oreitisrecommendedthat, forInternal_Servers,accessberestricted
throughtheuseofsystemlevelACLandapplicationlevelauthentication,rather
thanthroughfirewallfiltering.
Kommentare zu diesen Handbüchern