
YuChakTinMichael‘sGIACGCFWProjectAssignment
Page 105
ConfiguringtheProxyServer
Refertot he“ProductsPreparation”section forinformationonMicrosoftISAServer.
Refertot he“ProductsPreparation”section forinformationonWindows2000hardening.
ThissectionfocusesontheconfigurationofISAServer’sProxyfunctions.Infact,
ISAServer’sroleintermsoffirewallinginthisprojectissimpleandstraight
forward:DropALLincomingrequestsmadefromtheinternet!
TheinternalstaffsatGIACneedtoaccesstheinternetfrequently.Itisnoteconomical
norscalableiftrueIPisimplementedforeachclient.Ontheotherhand,simpleNAT
doesnotproduceanyperformancebenefit. Thus,aproxyserverthatcombinesNAT
andcachingshouldbeimplemented.
Aproxyserverisaserverthatsitsbetweenaclientapplicationandarealserverthat
interceptsallrequeststotherealservertoseeifitcanfulfilltherequestsitself.As
describedbyWebopedia.com,proxyservershavetwomainpurposes:
“ImprovePerformance:Proxyserverscandramaticallyimproveperformancefor
groupsofusers.Thisisbecauseitsavestheresultsofallrequestsforacertain
amountoftime.ConsiderthecasewherebothuserXanduserYaccesstheWorld
WideWebthroughaproxyserver.FirstuserXrequestsacertainWebpage,which
we'llcallPage1.Sometimelater,userYrequeststhesamepage.Insteadof
forwardingtherequesttotheWebserverwherePage1resides,whichcanbea
timeconsumingoperation,the proxyserversimplyreturnsthePage1thatitalready
fetchedforuserX.Sincetheproxyserverisoftenonthesamenetworkastheuser,this
isamuchfasteroperation.Realproxyserverssupporthundredsorthousandsofusers.
Themajoronline servicessuchasCompuserveandAmericaOnline,forexample,
employanarrayofproxyservers.
FilterRequests: Proxyserverscanal so beusedtofilterrequests.Forexample,a
companymightuseaproxyservertopreventitsemployeesfromaccessingaspecific
setof Websites.”
20
20
http://www.webopedia.com/TERM/P/proxy_server.html
Comentarios a estos manuales