
YuChakTinMichael‘sGIACGCFWProjectAssignment
Page 101
n “In”definestrafficfromRemotetoLocal
n “Out”definestrafficfromLocaltoRemote
IntheFilteringsection,definetheaddressrangesofthepartiesinvolvedintheaccess.
Theintranetwebservernetworkisonthelocalside.Itlistensonport80.Ontheother
hand,aHTTPclientusesaportabove1023toinitiaterequestfromtheremoteside.
Fragmentsshouldbeblocked,andrulesshouldbeeffectiveallthetime.However,do
NOTenable“Blockincomingconnections”,oranyconnectionattemptwillfail.
Komentarze do niniejszej Instrukcji