
YuChakTinMichael‘sGIACGCFWProjectAssignment
Page 186
businesscriticalapplicationsandendusers.FloodGate1canbedeployedwith
VPN1®/FireWall1®orstandalone. ”(fromwww.checkpoint.com
54
)
Or,ifcostisanissue,partial bandwidth controlcanbeexercisedviaISAServer’s
builtinBandwidthRules.KBarticle302527explainsindetailhowtoconfigurethis
feature
55
.Withthisfeatureenabled,bandwidthusageontheINETstream canbe
controlled.
Recommendatio nTwo
Faulttoleranceusingstandbysystemsisnotanoptimalsolution.Firstofall,
switchingtothestandbysysteminvolvescertaindowntime.Secondly,keepingthe
productionsystemandthestandbysysteminsyncisatimeconsumingmanualjob.
Therefore,advancedfaulttolerancesolutionshouldbeconsidered.BothNT4and
Windows2000AdvancedServereditionsupportclustering,apopularstrategyfor
connectingmultiplecomputerstogetherinsuchawaythattheybehaveasasingle
unit
56
.
Recommendatio nThree
ThereisnofaulttoleranceprovidedfortheWANlinks.TechnologysuchasDDR
shouldbeconsidered.WithDDR(DialonDemandRouting),thebackupconnection
onlybecomesactivewhen theprimarylinksfail
57
.
Recommendatio nFour
Regardlessofwhatfirewalltechnology isinuse,trafficisallowedtoflowtotheweb
serverviaport80and443.Thescriptsonthewebserverarepotentialsourcesof
varioussecurity threats
58
.Itisrecommendedthatanauditonalltheserverscriptsbe
performed.
54
http://www.checkpoint.com/products/performance/floodgate1.html
55
http://support.microsoft.com/view/tn.asp?kb=302527
56
http://www.webopedia.com/TERM/c/clustering.html
57
http://www.webopedia.com/TERM/D/DDR.html
58
“ProgrammingSecureScripts”,HackProofingYourEcommerceSite,ISBN:192899427X,
http://www.syngress.com/catalog/sg_main.cfm?pid=1216
Comentários a estes Manuais