
YuChakTinMichael‘sGIACGCFWProjectAssignment
Page 82
Ifthelogfilegrowstoobig(thisispossibleinabusynetwork),considertostarta
newlogfile.Whenanewlogfileisstarted,thecurrentonewillbeautomatically
savedwithanamethathasthecurrentdateappendedtoit.
Apartfromthelog,wemay,throughtheSystemStatusinterface,watchinrealtime
thenumberofpacketsthatareDropped,Rejected,InspectedandLogged.
ConfiguringtheR ulebaseforFW2_B2C:
Refertot he“ProductsPreparation”section on FW1and WindowsNT hardening.
SecurityPoliciesandOrders:
FW2_B2Cisthesecondlayerof firewall protection againstoutsideintrusionalong
theB2Clink.Italsopreventstheinternalstaffsfromtamperingwiththepublic
serviceservers. Thesecuritypolicieshereinclude:
1,Ecommercewebservice:
n AnytrafficallowedfromInternal_Admin.
n HTTP/HTTPStrafficallowedfrom Internal_Dev (DevelopersuseHTTP/HTTPS
basedupdatemethodsuchasFrontpageServerextension).
n HTTP/HTTPStrafficallowedfromInternal_Clients.
n HTTP/HTTPStrafficallowedfromRAS_Net.
2,Externalemailservice:
n Anytrafficallowedfrom Internal_Admin.
n SMTPtrafficallowedfromtheinternalemailserverforretrievingandsending
emailstoandfromtheoutsideworld.
3,External DNSservice:
n Anytrafficallowedfrom Internal_Admin.
n DNSquery trafficallowedfromInternal_Dev.
n DNSquerytrafficallowedfromInternal_Clients.
n DNSquerytrafficallowedfromRAS_Net.
4,IDS:
Comentários a estes Manuais