
YuChakTinMichael‘sGIACGCFWProjectAssignment
Page 133
ConfiguringtheR ASServer
TheRAS_NetRASserverisa“backdoor”tothenetwork. Itallowsthecompany
staffstoremoteaccessingtheserverresourcesinInternal_Serversaswellastoaccess
thecompany’sPublic_Servicesservers.Userswithoutformalaccountsinthedomain
controllerarenotallowedtologinviaRAS.
SecurityPolicy:
1. Onlylegitimateuserswiththevalidcredentialsandfromthevaliddialing
locationsareallowedtologin.
2. Disalloweverythingelse.
RASConfiguration:
ThisRASserverwillbeconfiguredwithapoolof 5modemsand5clientIPaddresses
(thatbelongstotheRAS_Netsubnet)forallocationtothedialinclients. Theseclients
areforcedtotakeandusetheseaddresses.Thecorrespondingfirewallfiltersat
VisNetic_1areconfiguredbasedtomakefilteringdecisionsbasedon theseaddresses.
TomakesurethatthisRASserverdoesnotconstituteasecurityhole,wemust:
n Takestepstoharden this Windows2000system.Refertothe“Products
Preparation”sectionforinformationonhowtoproceed.
n ConfigurethecorrespondingRemoteAccessPoliciesandrequiresstrong
encryptionaswellasstrongauthentication.
n Configureaccountlockoutpolicy torestrictthenumberofloginattempts
allowed.
n Configurethesystemtoacceptincomingcallsonlyfrompredefinednumbers,
andusecallbacksecuritytoensurethatonlythe“trueemployees”andnoone
elsecandialin.
Withremoteaccesspolicies,aconnectionisauthorizedonlyifthesettingsofthe
connectionattempttomatchatleastoneoftheremoteaccesspolicies.Accordingto
Comentarios a estos manuales