
YuChakTinMichael‘sGIACGCFWProjectAssignment
Page 161
n nonHTTP/HTTPStrafficfromInternal_Clients.
n nonHTTP/HTTPStrafficfromRAS_Net.
n HTTP/HTTPStrafficfromanewunknownsubnet.
Initiatethefollowingconnectionstowardstheexternalemailserviceserver:
n nonSMTPtrafficfromtheinternalserversegment
n POP3 trafficfromtheinternalclientssegment
Allconnectionsfailed.Thisisthedesirableresult.
InitiatethefollowingconnectionstowardstheexternalDNSserviceserver:
n nonDNSquerytrafficfromInternal_Dev.
n nonDNSquerytrafficfromInternal_Clients.
n nonDNSquerytrafficfromRAS_Net.
Allconnectionsfailed.Thisisthedesirableresult.
InitiatenonSMTPconnectionstowardstheinternalemailserverfromtheIDS.
Connectionssucceeded.Thisisthedesirableresult.
InitiateSMTPconnectionstowardstheIDSfromtheinternalemailserver.
Connectionsfailed.Thisisthedesirableresult.
DeliberatelytriggertheIDStosendanalert.Seeifthemessagecanreachthe
internalSMTPserver.
Messagearrivedattheadministrator’smailbox
successfully.
Otherassessmentmethods
NSLOOKUP –initiateazonetransferagainsttheDNSserverbehindthefirewall
frominternal_clients. AccordingtoMicrosoft’sKBArticleQ200525:
Thezonetransferoperationfails.Suchafailureisa
desirablebehavior.Attemptlogged.
47
http://support.microsoft.com/search/preview.aspx?scid=kb;enus;Q200525
Comentários a estes Manuais