Firewall Policies/Rulesets phần 2

Because the DMZ has a single interface for all traffic going to either the Internet or the internal network | Figure 10-4. One-Armed DMZ and ACLs View full size image Because the DMZ has a single interface for all traffic going to either the Internet or the internal network building and applying an ACL to that interface will functionally act as an ingress filter to the internal network but as an egress filter to the Internet. This will make the ACL even more complex to design and implement. The good news is that the same seven steps in building an effective ACL for traffic from the Internet to the DMZ should be applied in this situation so the methodology remains consistent. Access from the Internet to an Internal Segment Building an ACL to control traffic from the Internet to an internal segment is functionally no different from the previously discussed ACL scenarios. What differs however is that the traffic is going to come from a completely untrusted network and potentially have direct access to internal resources. Now the knee-jerk response to this type of implementation is to simply not allow it. I have found that there are few constants in network security however and whereas 99 percent of the situations that call for direct access to internal resources can probably be worked around in another fashion there is always that 1 percent that for whatever reason you just cannot do anything about. In those cases you need to be absolutely certain of what you are allowing through the use of your ingress filter. Additionally although technically not an ingress-filtering issue you should strongly consider using a firewall that does a true application proxy of the service you are advertising to ensure that only the kind of communications at the application layer that you want to permit are indeed being permitted. An example of this is something like the Microsoft ISA Firewall using its application publishing features to grant access to the resource. Egress Filters Practically speaking egress filters are almost identical to ingress filters. The difference lies in what an egress .

Không thể tạo bản xem trước, hãy bấm tải xuống
TÀI LIỆU MỚI ĐĂNG
187    27    1    03-12-2024
Đã phát hiện trình chặn quảng cáo AdBlock
Trang web này phụ thuộc vào doanh thu từ số lần hiển thị quảng cáo để tồn tại. Vui lòng tắt trình chặn quảng cáo của bạn hoặc tạm dừng tính năng chặn quảng cáo cho trang web này.