Eicon Networks S92 Manuel d'utilisateur Page 131

  • Télécharger
  • Ajouter à mon manuel
  • Imprimer
  • Page
    / 209
  • Table des matières
  • MARQUE LIVRES
  • Noté. / 5. Basé sur avis des utilisateurs
Vue de la page 130
YuChakTinMichael‘sGIACGCFWProjectAssignment
Page 131
headerssothatitappearsthatthepacketsarecomingfromthathost.”
30
DetailedinformationonIPSpoofingisavailableat:
IPspoofingDemystified:http://www.fc.net/phrack/files/p48/p4814.html
TopreventincomingIPpacketslabeledwith“internal”IPaddressesfromenteringthe
networkviatheWANadaptor,configurefiltersontheWANadaptorS92witheach
DirectionsettoIN,ActiontoDrop,Source IPAddresstotheinternaladdresses,and
SourceMaskto255.255.255.255:
IN,DROP,Source:Core_Net(192.168.16.0),Mask:255.255.255.255
IN,DROP,Source:Public_Services(192.168.8.0),Mask:255.255.255.255
IN,DROP,Source: Internal_Clients(192.168.17.0),Mask:255.255.255.255
IN,DROP,Source: Internal_Servers(192.168.18.0),Mask:255.255.255.255
IN,DROP,Source: Internal_Admin(192.168.19.0),Mask:255.255.255.255
IN,DROP,Source: Internal_Dev(192.168.20.0),Mask:255.255.255.255
IN,DROP,Source:Critical_Resources(192.168.21.0),Mask:255.255.255.255
IN,DROP,Source:RAS_Net(192.168.22.0),Mask:255.255.255.255
Thefiltersareprocessedsequentially.Forourrules,sincetheaddressesdonot
overlap,therearenoconflictsbetweenthem,andtheorderwouldthereforebe
irrelevant.
BasicTesting
n Configureaclientwithanaddressfrom Internal_Clients.Connectfromthe
outsidetotheWWWserverinPublic_ServicesviaHTTP.Thepacketshouldbe
droppedrightatRouter_Eiconcard.
n Configureaclientwithanaddressfrom Internal_Dev.Connectfromtheoutside
totheDNSserverinPublic_ServicesviaNSLOOKUP.Thepacketshouldbe
droppedrightatRouter_Eiconcard.
n Configureaclientwithanaddressfromtheoutsideworld.Connectfromthe
outsidetotheWWWserverinPublic_ServicesviaHTTP.Thepacketshouldbe
allowedtopassthroughatRouter_Eiconcard.
n FromavalidclientinInternal_Admin,connecttotheoutsideworld.Therequest
30
http://www.webopedia.com/TERM/s/spoof.html
Vue de la page 130
1 2 ... 126 127 128 129 130 131 132 133 134 135 136 ... 208 209

Commentaires sur ces manuels

Pas de commentaire