
YuChakTinMichael‘sGIACGCFWProjectAssignment
Page 103
LocalInterfaceConfiguration:
AtVisNetic_1,wearetryingtoprotectthefollowingtrustedsubnets:
n Internal_Servers(192.168.18.0)
n Critical_Resources(192.168.21.0)
Thesesubnetsaretobetreatedaslocal bytherespectiveinterfacesofVisNetic_1:
n 192.168.18.0– trustedby192.168.18.1
n 192.168.21.0– trustedby192.168.21.1
Thus,interface192.168.18.1 and192.168.21.1shouldbeconfiguredtoallowall
traffic.Ontheotherhand,RAS_Net(192.168.22.0)includesdialinusers,andis
consideredasremoteanduntrusted.
ExternalInterfaceConfiguration:
Now,weneedtodeterminetheremotesubnetsthatneedtoaccessthetrustedsubnets
listedinthelastsection.OneobviousexternalinterfaceonVisNetic_1is192.168.16.6,
whichistheCore_Netconnectedtothecoreswitch.Onthisinterfacetrafficmustbe
filtered,withrulesbeingconfiguredasfollow(segmentontheleftrepresentsthelocal
side,whiletheoneontherightrepresentstheremoteside):
n Internal_Servers(192.168.18.0) < IN&OUT,MicrosoftNetworking,DNS
Query,SMTP,POP3,HTTP,FTP >Internal_Clients(192.168.17.0)
n Internal_Servers(192.168.18.0) < IN&OUT,MicrosoftNetworking,DNS
Query,SMTP,POP3,HTTP,FTP >Internal_Dev(192.168.20.0)
n Critical_Resources(192.168.21.0) < IN&OUT,HTTP andHTTPS >
Internal_Clients(192.168.17.0)
n Critical_Resources(192.168.21.0)< IN&OUT,HTTPandHTTPS >
Internal_Dev(192.168.17.0)
n Critical_Resources(192.168.21.0) < IN&OUT,HTTP andHTTPS >
Core_NetVPNClients(Addressrange:192.168.16.55to192.168.16.65)
n Any<IN&OUT,Any >Internal_Admin(192.168.19.0)
Comentários a estes Manuais