Eicon Networks S92 Uživatelský manuál Strana 40

  • Stažení
  • Přidat do mých příruček
  • Tisk
  • Strana
    / 209
  • Tabulka s obsahem
  • KNIHY
  • Hodnocené. / 5. Na základě hodnocení zákazníků
Zobrazit stránku 39
YuChakTinMichael‘sGIACGCFWProjectAssignment
Page 40
inspectiontechnology.Aformofdynamicpacketfiltering,statefulinspectionworks
atthenetworklayerandtrackseachconnectiontraversingallinterfacesofthefirewall
tomakesuretheyarevalid.
Statefulinspectionis“superior”asitexaminesnotonlythepacketheaderbutalsothe
packetcontents.Suchinspectionisdoneallthewayuptotheapplicationlayer,
makingitpossibleforfilteringdecisionstobemadebasedoncontextthathasbeen
establishedbypriorpassedpackets.Asameasureagainstportscanning,stateful
inspectionfirewallsalwayscloseoffportsuntilconnectiontothespecificportis
requested.
ForthisprojectIusedFW1version4.0forx86,whichisnotcurrentbutiswhatI
haveonhand.ItrunsonWindowsNTServer4.0.Tomakethisfirewallsystemtruly
secure,thethingsthatneedtobedoneare:
n HardeningNTitself –applyallthelatestservicepacks,patchesandfixes;and
disablealltheunnecessaryservicesandcomponents.
n SecuringFW1–again,applyallthelatestpatchesandfixesforversion4.
Hardeni ngtheNTInstallation
AccordingtoCERT’sNTconfigurationguidelines,therearetwotypesofpatches
fromMicrosoft:ServicePacksandHotfixes.Servicepacksareforpatchingawide
rangeofvulnerabilitiesandbugs,whilehotfixesarereleasedmorefrequentlythan
servicepacksandareforpatchingmorespecificproblems
5
.
Keepinmindthough,thatservicepacksarecumulative,meaningweonlyneedto
installthelatestServicePack.Forfixes,however,weneedtodeterminewhatto
install(aswewon’tneedallofthem).ServicePackmustbeinstalledbeforethe
Hotfixes.
Wemayaccessalltheseservicepacksandupdatesfromacentrallocation:
http://www.microsoft.com/ntserver/nts/downloads/default.asp#RecommendedUpdates.
5
http://www.cert.org/tech_tips/win_configuration_guidelines.html
Zobrazit stránku 39
1 2 ... 35 36 37 38 39 40 41 42 43 44 45 ... 208 209

Komentáře k této Příručce

Žádné komentáře