Eicon Networks S92 Manual de usuario Pagina 133

  • Descarga
  • Añadir a mis manuales
  • Imprimir
  • Pagina
    / 209
  • Tabla de contenidos
  • MARCADORES
  • Valorado. / 5. Basado en revisión del cliente
Vista de pagina 132
YuChakTinMichael‘sGIACGCFWProjectAssignment
Page 133
ConfiguringtheR ASServer
TheRAS_NetRASserverisa“backdoor”tothenetwork. Itallowsthecompany
staffstoremoteaccessingtheserverresourcesinInternal_Serversaswellastoaccess
thecompanysPublic_Servicesservers.Userswithoutformalaccountsinthedomain
controllerarenotallowedtologinviaRAS.
SecurityPolicy:
1. Onlylegitimateuserswiththevalidcredentialsandfromthevaliddialing
locationsareallowedtologin.
2. Disalloweverythingelse.
RASConfiguration:
ThisRASserverwillbeconfiguredwithapoolof 5modemsand5clientIPaddresses
(thatbelongstotheRAS_Netsubnet)forallocationtothedialinclients. Theseclients
areforcedtotakeandusetheseaddresses.Thecorrespondingfirewallfiltersat
VisNetic_1areconfiguredbasedtomakefilteringdecisionsbasedon theseaddresses.
TomakesurethatthisRASserverdoesnotconstituteasecurityhole,wemust:
n Takestepstoharden this Windows2000system.Refertothe“Products
Preparation”sectionforinformationonhowtoproceed.
n ConfigurethecorrespondingRemoteAccessPoliciesandrequiresstrong
encryptionaswellasstrongauthentication.
n Configureaccountlockoutpolicy torestrictthenumberofloginattempts
allowed.
n Configurethesystemtoacceptincomingcallsonlyfrompredefinednumbers,
andusecallbacksecuritytoensurethatonlythe“trueemployees”andnoone
elsecandialin.
Withremoteaccesspolicies,aconnectionisauthorizedonlyifthesettingsofthe
connectionattempttomatchatleastoneoftheremoteaccesspolicies.Accordingto
Vista de pagina 132
1 2 ... 128 129 130 131 132 133 134 135 136 137 138 ... 208 209

Comentarios a estos manuales

Sin comentarios