
YuChakTinMichael‘sGIACGCFWProjectAssignment
Page 37
5. RASuserswhoconnectviaRAS_NetcanaccesstheInternal_Serverssegment
withanyprotocol,althoughtheiraccessmustberestrictedbysystemlevel
authenticationandauthorization.TheiraccesstoPublic_Servicesissubjectto
filteringatFW2_B2C.
6. Dropandlogeverythingelse.
PoliciesatW2K_VPN
1. OnlyPPTPconnectionsfromthelegitimateexternalpartners/suppliersare
allowed.
2. Nootherinbound/outboundtraffictypesareallowedthroughthisrouter.That
means,dropandlogeverythingelse.
PoliciesatNorton1_IDS
1. NoconnectiontowardsInternal_Clientscaneverbeinitiatedfromanyother
segment(exceptfromInternal_Admin).
2. Outboundaccessrequestsmadeby Internal_Clientsarenotrestrictedbythis
firewall,butbyotherfirewallsonthenetwork.
3. Whentheclientsaccesstheinternet,JavaandActiveXcodesareblocked.
4. Dropandlogeverythingelse.
PoliciesatNorton2_IDS
1. NoconnectiontowardsInternal_Admincaneverbeinitiatedfromanyother
segment.
2. Outboundaccessrequestsmadeby Internal_Admin arenotrestrictedbythis
firewall.
3. Whentheadministratorsaccesstheinternet,JavaandActiveXcodesare
blocked.
4. Dropandlogeverythingelse.
PoliciesatNorton3_IDS
1. NoconnectiontowardsInternal_Dev caneverbeinitiatedfromanyother
Comentarios a estos manuales