
YuChakTinMichael‘sGIACGCFWProjectAssignment
Page 100
AnInterfaceConfigurationExample:
Asmentionedbefore,VisNetichasitsrulesconfiguredonaperinterfacebasis.FOR
EXAMPLE,ifaruleisneededtoallowHTTPaccessfromtheclientsin192.168.16.0
totheintranetwebserverin 192.168.18.0,thefollowinginterfaceconfigurationsmust
bemade:
1,
Configuretheinterfaceattachedto192.168.18.0toacceptalltraffics.192.168.18.0is
consideredasatrustedlocalnetworktothefirewall(whilethe192.168.16.0network
isconsideredasuntrustedandremote).
2,
Configuretheinterfaceattachedto192.168.16.0tofilteralltraffics.Bydoingso,all
trafficwillbeblockedbythisinterfaceUNLESSrulesareconfiguredtoallow
exceptions.
3,
AddanewruletoallowHTTPaccess.ThisinvolvestheTCPprotocolwitha“In&
Out”nature:
Komentáře k této Příručce