YuChakTinMichael‘sGIACGCFWProjectAssignment
Page 93
ConfiguretheSecurityLevel:
Weneedthehighestpossiblelevelofsecurityhere.Tosetsuchsecurity,useCustom
Settings,andsetevery blockingoption toHigh.Allthealertoptionsshouldbe
enabledaswell.
ConfiguretheAdvancedOptions:
Inthe AdvancedOptionssection,enablethefollowingoptions:
n BlockIGMPProtocol:IPmulticastisnottobeusedinournetworkanyway,so
thisoptionshouldbeblocked.
n StealthBlockedPorts:Thiscausestheblockedportstonotrespondtoenquiries
fromtheoutside.Suchoptioneliminatesthehacker’sopportunityoflearningany
unnecessarynetworkinformation.
n BlockFragmentedIPPackets:FragmentedIPpacketsareoftenusedasawayto
attacksystems.Thisoptiondisablessuchthreat.
ConfigureIntrusionDetection:
NortonFirewallcandetectportscanattemptsandautomaticallyblocktheattackers
frommakingfurtherconnectionattempts. Enableallofthesefeatures.
ConfigureLogging:
Weshouldalwaysoptforloggingasmuchinformationaspossible.SettheReporting
LeveltoHighandensurethatyourdriveislargeenoughtoholdthelargeamountof
loggeddata.
BasicTesting:
n FromInternal_Admin,accessafileshareinInternal_Servers.Therequestshould
succeed.
n FromInternal_Admin,accessaninternetwebsiteviaISA_Cache’sport8080.
Therequestshouldsucceed.
n FromRAS_Net,accessafileshareinInternal_Admin.Therequestshouldfail.
n Inspectthelogfile.
Commentaires sur ces manuels