
YuChakTinMichael‘sGIACGCFWProjectAssignment
Page 92
ConfiguringtheN orton2_IDSFirewall:
Refertot he“ProductsPreparation”section forinformationonNortonPersonalFirewall2002.
Refertot he“ProductsPreparation”section forinformationonWindows2000hardening.
Norton2_IDSsitsbetweentheinternal coreswitch andtheInternal_Adminsegment.
SecurityPolicy:
Thepoliciestobeenforcedhereare:
1. NoconnectiontowardsInternal_Admincaneverbeinitiatedfromanyother
segment.
2. OutboundaccessrequestsmadebyInternal_Adminarenotrestrictedbythis
firewall.
3. Whentheadministratorsaccesstheinternet,JavaandActiveXcodesare
blocked.
4. Dropandlogeverythingelse.
DefiningtheZones:
n Inournetwork, Internal_Admin(192.168.19.0) canaccessanywhere. Therefore,
192.168.19.0mustbe Trusted.
n Norequeststowards Internal_AdmincaneverbemadefromInternal_Clients
(192.168.17.0), Internal_Dev(192.168.20.0),Critical_Resources(192.168.21.0),
Public_Services(192.168.8.0),RAS_Net(192.168.22.0)nor Core_Net
(192.168.16.0). Thesesubnetsshouldall beRestricted.
n WhetherornottrafficcanbeinitiatedfromInternal_Serversdependsonthe
serverapplicationsinuse.SinceInternal_Serversisprettysecureunderthe
protectionoftheVisNeticfirewall,andjustincasethatcertainmaintenance
traffichastooriginatefromtheserverstotheclients,wewillhave
Internal_Servers(192.168.18.0)configuredasTrusted.
Comentarios a estos manuales