
YuChakTinMichael‘sGIACGCFWProjectAssignment
Page 69
NetworkObjects:
Beforewesetupanyrule,alltherelevantnetworkobjectsmustbebuiltfirst. The
followingissuesmustbeconsidered:
n TheIDSis“invisible”totheoutsideworld,andisnotneededinthisrulebase.
n NATisneededfortheEcommercewebserver,theEmailserverandtheDNS
server.
n FW1supportsantispoofingbyautomaticallygeneratingrulesthatrejectpackets
withinternalIPaddressesarrivingontheexternalinterface.Forthisfeatureto
work,theInterfacespropertiesmustbeproperlyconfiguredsothatwhatis
consideredtobeinternalisclearlydefined.
WWW
n TheEcommercewebserver
n Theserver’saddressinthenetworkis192.168.8.3.
n Theserver’s“public”addressforoutsideaccessis192.168.7.8.Thismustbe
definedviatheNATtab.ThecorrespondingNATruleswillbeautomatically
generated.
n Internaltothefirewall
Comentarios a estos manuales