Eicon Networks S92 Manuel d'utilisateur Page 133

  • Télécharger
  • Ajouter à mon manuel
  • Imprimer
  • Page
    / 209
  • Table des matières
  • MARQUE LIVRES
  • Noté. / 5. Basé sur avis des utilisateurs
Vue de la page 132
YuChakTinMichael‘sGIACGCFWProjectAssignment
Page 133
ConfiguringtheR ASServer
TheRAS_NetRASserverisa“backdoor”tothenetwork. Itallowsthecompany
staffstoremoteaccessingtheserverresourcesinInternal_Serversaswellastoaccess
thecompanysPublic_Servicesservers.Userswithoutformalaccountsinthedomain
controllerarenotallowedtologinviaRAS.
SecurityPolicy:
1. Onlylegitimateuserswiththevalidcredentialsandfromthevaliddialing
locationsareallowedtologin.
2. Disalloweverythingelse.
RASConfiguration:
ThisRASserverwillbeconfiguredwithapoolof 5modemsand5clientIPaddresses
(thatbelongstotheRAS_Netsubnet)forallocationtothedialinclients. Theseclients
areforcedtotakeandusetheseaddresses.Thecorrespondingfirewallfiltersat
VisNetic_1areconfiguredbasedtomakefilteringdecisionsbasedon theseaddresses.
TomakesurethatthisRASserverdoesnotconstituteasecurityhole,wemust:
n Takestepstoharden this Windows2000system.Refertothe“Products
Preparation”sectionforinformationonhowtoproceed.
n ConfigurethecorrespondingRemoteAccessPoliciesandrequiresstrong
encryptionaswellasstrongauthentication.
n Configureaccountlockoutpolicy torestrictthenumberofloginattempts
allowed.
n Configurethesystemtoacceptincomingcallsonlyfrompredefinednumbers,
andusecallbacksecuritytoensurethatonlythe“trueemployees”andnoone
elsecandialin.
Withremoteaccesspolicies,aconnectionisauthorizedonlyifthesettingsofthe
connectionattempttomatchatleastoneoftheremoteaccesspolicies.Accordingto
Vue de la page 132
1 2 ... 128 129 130 131 132 133 134 135 136 137 138 ... 208 209

Commentaires sur ces manuels

Pas de commentaire