Eicon Networks S92 Manuel d'utilisateur Page 128

  • Télécharger
  • Ajouter à mon manuel
  • Imprimer
  • Page
    / 209
  • Table des matières
  • MARQUE LIVRES
  • Noté. / 5. Basé sur avis des utilisateurs
Vue de la page 127
YuChakTinMichael‘sGIACGCFWProjectAssignment
Page 128
Foradditionalprotection,wewanttosetthefilterstoallowconnectionsonlyfromthe
externalpartners/suppliers’IPnetworks. Thisrequiresthattheexternalclients’IP
configurationsbefullycommunicatedwithGIAC.
ConfigureOutputFilters:
PPTP outputpacketfiltersaretobeconfiguredontheadapterthatisonthesideof the
Internetaswell(192.168.6.2).
Thisinterface’sOutputFiltersshouldbeconfiguredsothatthefilteractionissetto
Dropallpacketsexceptthosethatmeetthecriteriabelow:
n SourceIPaddressoftheVPNserver'sInternetinterface(192.168.6.2),subnet
maskof255.255.255.255,andTCPsourceportof1723.ThisallowsPPTPtunnel
maintenancetrafficfromtheVPNservertotheVPNclients.
n SourceIPaddressoftheVPNserver'sInternetinterface(192.168.6.2),subnet
maskof255.255.255.255,andIPProtocolIDof47.ThisallowsPPTPtunneled
datafromtheVPNservertotheVPNclients.
BasicTesting: 
n ConnectfromavalidVPNclienttoPublic_Servicesbygoingthrough
W2K_VPN.UseL2TPinsteadofPPTP.Theconnectionattemptshouldfail.
n ConnectfromavalidVPNclienttoPublic_Servicesbygoingthrough
W2K_VPN.UsePPTP.AccessthedatabaseapplicationusingHTTP.The
connectionattemptshouldsucceed.
n ConnectfromanonvalidVPNclienttoPublic_Servicesbygoingthrough
W2K_VPN.UsePPTP.AccessthedatabaseapplicationusingHTTP.The
connectionattemptshouldfail.
n InspecttheRASlogfile.
FurthertestingshouldbeconductedattheAuditstage.
Vue de la page 127
1 2 ... 123 124 125 126 127 128 129 130 131 132 133 ... 208 209

Commentaires sur ces manuels

Pas de commentaire