
YuChakTinMichael‘sGIACGCFWProjectAssignment
Page 78
ThepossiblestatusesoftheFirewall1Daemonare:
n INSTALLED,meaningthedaemonisrunningandthatthesecuritypolicyis
installed
n NOTINSTALLED,meaningthedaemonisrunning,butthenthesecuritypolicy
isnotinstalled
n DISCONNECTED,meaningthereisnoresponsefromthedaemonatall.Most
likelythedaemonhascrashed.
6,
Configurerouting.SinceNAToccursAFTERinternalrouting(andBEFORE
transmission),wemustmanuallysetuptherequiredpersistentroutestoensurethat
NATcanbecorrectlyperformed.
ForWWW,thecommandtouseinNT’sCommandPromptis:
routeadd–p192.168.7.8192.168.8.3
ForDNS,thecommandtouseinNT’sCommandPromptis:
routeadd–p192.168.7.9192.168.8.4
ForEmail,thecommandtouseinNT’sCommandPromptis:
routeadd–p192.168.7.10192.168.8.5
The–pswitchensuresthattheseentriescansurviverebootsbyhavingthemstoredas
persistententries.
7,
Performsomebasictesting:
TotesttheHTTP/HTTPSrule,dothefollowing:
n DeliberatelysetuptelnetandFTPservicestorunontheWWWserver.Fromthe
outside,connecttoWWWviaFTPandTelnet.Theconnectionrequestsshould
fail.
n Fromtheoutside,connecttoWWWviaHTTPandHTTPS.Theconnection
requestsshouldsucceed.
Comentários a estes Manuais