
YuChakTinMichael‘sGIACGCFWProjectAssignment
Page 96
Internal_Servers(192.168.18.0)configuredasTrusted.
ConfiguretheSecurityLevel:
Weneedthehighestpossiblelevelofsecurityhere. Tosetsuchsecurity,useCustom
Settings,andseteveryblockingoptiontoHigh.Allthealertoptionsshouldbe
enabledaswell.
ConfiguretheAdvancedOptions:
IntheAdvancedOptionssection,enablethefollowingoptions:
n BlockIGMPProtocol:IPmulticastisnottobeusedinournetworkanyway,so
thisoptionshouldbeblocked.
n StealthBlockedPorts:Thiscausestheblockedportstonotrespondtoenquiries
fromtheoutside.Suchoptioneliminatesthehacker’sopportunityoflearningany
unnecessary networkinformation.
n BlockFragmentedIPPackets:FragmentedIPpacketsareoftenusedasawayto
attacksystems.Thisoptiondisablessuchthreat.
ConfigureIntrusionDetection:
NortonFirewallcandetectportscanattemptsandautomaticallyblocktheattackers
frommakingfurtherconnectionattempts.
ConfigureLogging:
Weshouldalwaysoptforloggingasmuchinformationaspossible.SettheReporting
LeveltoHighandensurethatyourdriveislargeenoughtoholdthelargeamountof
loggeddata.
BasicTesting:
n FromInternal_Dev,accessafileshareinInternal_Servers.Therequestshould
succeed.
n FromInternal_Dev,accessaninternetwebsiteviaISA_Cache’sport8080.The
Komentarze do niniejszej Instrukcji