Eicon Networks S92 Instrukcja Użytkownika Strona 83

  • Pobierz
  • Dodaj do moich podręczników
  • Drukuj
  • Strona
    / 209
  • Spis treści
  • BOOKMARKI
  • Oceniono. / 5. Na podstawie oceny klientów
Przeglądanie stron 82
YuChakTinMichael‘sGIACGCFWProjectAssignment
Page 83
n TheIDScanalertInternal_AdminviaSMTP.
n Snort(http://www.snort.org/)isanidealIDSsoftwareforsuchpurpose.
n Tobesecure,theIDSitselfishardenedandisprotectedbyafirewallservice
runningonitself.
n TheIDShasitsown SMTPservicesolelyforsendingalerts sendingemailsto
theadministratorsmailboxlocatedintheinternalemailserver.
5,Dropandlogeverythingelse.
Sincetheabovepoliciesarenotinconflicts,theorderdoesnotreallymatteraslong
asthe“dropeverythingelse”ruleisthelastrule.However,itisadvisedthatthemost
frequentlyencounteredrulesbeplacedatthetop.Thewebservice,inthecaseof
GIAC,issupposedtobethebusiestone.
NetworkObjects:
Beforewesetupanyrule,all therelevantnetworkobjectsmustbebuiltfirst.Notethat
NATisnotneededonthisconfiguration:
Admin
n Theinternaladministratorsnetworkobject
n Thenetworkaddressis192.168.19.0
n Internaltothefirewall
Dev
n Theinhousedevelopersnetworkobject
n Thenetworkaddressis192.168.20.0
n Internaltothefirewall
Staff
n Theinhouseclientsnetworkobject
n Thenetworkaddressis192.168.17.0
n Internaltothefirewall
RAS_User
n TheRASusersfromtheRAS_Netnetworkobject
n Thenetworkaddressis192.168.22.0
Przeglądanie stron 82
1 2 ... 78 79 80 81 82 83 84 85 86 87 88 ... 208 209

Komentarze do niniejszej Instrukcji

Brak uwag