
YuChakTinMichael‘sGIACGCFWProjectAssignment
Page 128
Foradditionalprotection,wewanttosetthefilterstoallowconnectionsonlyfromthe
externalpartners/suppliers’IPnetworks. Thisrequiresthattheexternalclients’IP
configurationsbefullycommunicatedwithGIAC.
ConfigureOutputFilters:
PPTP outputpacketfiltersaretobeconfiguredontheadapterthatisonthesideof the
Internetaswell(192.168.6.2).
Thisinterface’sOutputFiltersshouldbeconfiguredsothatthefilteractionissetto
Dropallpacketsexceptthosethatmeetthecriteriabelow:
n SourceIPaddressoftheVPNserver'sInternetinterface(192.168.6.2),subnet
maskof255.255.255.255,andTCPsourceportof1723.ThisallowsPPTPtunnel
maintenancetrafficfromtheVPNservertotheVPNclients.
n SourceIPaddressoftheVPNserver'sInternetinterface(192.168.6.2),subnet
maskof255.255.255.255,andIPProtocolIDof47.ThisallowsPPTPtunneled
datafromtheVPNservertotheVPNclients.
BasicTesting:
n ConnectfromavalidVPNclienttoPublic_Servicesbygoingthrough
W2K_VPN.UseL2TPinsteadofPPTP.Theconnectionattemptshouldfail.
n ConnectfromavalidVPNclienttoPublic_Servicesbygoingthrough
W2K_VPN.UsePPTP.AccessthedatabaseapplicationusingHTTP.The
connectionattemptshouldsucceed.
n ConnectfromanonvalidVPNclienttoPublic_Servicesbygoingthrough
W2K_VPN.UsePPTP.AccessthedatabaseapplicationusingHTTP.The
connectionattemptshouldfail.
n InspecttheRASlogfile.
FurthertestingshouldbeconductedattheAuditstage.
Comentarios a estos manuales