Eicon Networks S92 Manual de usuario Pagina 99

  • Descarga
  • Añadir a mis manuales
  • Imprimir
  • Pagina
    / 209
  • Tabla de contenidos
  • MARCADORES
  • Valorado. / 5. Basado en revisión del cliente
Vista de pagina 98
YuChakTinMichael‘sGIACGCFWProjectAssignment
Page 99
FW1.
DefiningtheInterfaces:
VisNetichasitsrulesconfiguredonaperinterfacebasis.So,fortraffictopass
throughitandobtainafeedbackfromtheotherside,configurationmustbemadeon
all theinterfacesinvolved.
VisNetic_1hasthefollowinginterfaces:
n 192.168.16.6(tothecoreswitch/Core_Net)
n 192.168.18.1(toInternal_Servers)
n 192.168.21.1(toCritical_Resources)
n 192.168.22.1(toRAS_Net)
TheConfigurationWizardcanbeusedtoputtheidleinterfacestoan “unused”state.
Wecannotrelysolelyonthefirewalltoprovideallsortsof protections!!!
IhaveallowedInternal_Clients,Internal_DevandRAS_Netusersaccessto
Internal_Serverswithwhateverprotocolstheylike.Therationalesare:
n TherearesomanydifferenttypesofservicespossibleinaMicrosoftWindows
basedNetwork,thatmanyoftheseservicesrelyonmultiple protocolsthatare
mutuallydependent.Blockingtheseprotocolsonebyoneispossible,butis
imposingheavyadministrativeburden,especiallywhennewapplications
usingnewprotocolsareregularlyintroduced(given thepaceoftechnological
advance,thisishighlylikelypossible).
n DifferentusersintheInternal_Clientsgrouprequiresaccesstodifferent
services.Blockingatthefirewallcanbeinflexibleandtroublesome.
Theref oreitisrecommendedthat, forInternal_Servers,accessberestricted
throughtheuseofsystemlevelACLandapplicationlevelauthentication,rather
thanthroughfirewallfiltering.
Vista de pagina 98
1 2 ... 94 95 96 97 98 99 100 101 102 103 104 ... 208 209

Comentarios a estos manuales

Sin comentarios