Network Security - An overview
Except on the first page, right running head:
Heading1 or Heading1NewPage text (automatic)
651
Alcatel-Lucent
Beta
Beta
CLI Configuration Guide
B
EFORE
Y
OU
C
ONFIGURE
F
ILTERS
AND
F
IREWALLS
1.
The identification of the risk level and the type of access required of each network
system forms the basis before setting up the firewall.
2.
Create Usage Policy Statements: Create Usage Policy Statements that outline
users' roles and responsibilities with regard to security. Start with a general policy
that covers all network systems and data.
3.
Before you configure firewall, keep in mind to maintain a workable balance
between security and required network access.
4.
You should also be sure that you have a thorough understanding of the IP
protocol, port numbers, host address mapping, and other related basic firewall
technologies.
5.
Configure the common classifiers first based on the usage policy statements.
(Refer to the
“Common Classifiers”
chapter in this guide).
6.
Configure the firewall with necessary parameters for scheduling, policy
statements, stateful inspection, session management, etc.
OA-700 S
PECIFIC
O
VERVIEW
•
For
OA-700
, the default action for a filter is
“deny”
. However, you can change this
option by using the keyword “
permit
”.
•
OA-700, by default, supports “
stateful inspection
”. To convert it to a stateless
inspection firewall, use the keyword “
stateless
”.
•
If no rules (match cases) are defined, the
default
keyword can be used to just
configure a
permit
or
deny
on all incoming and outgoing traffic.
•
Filtering takes place only when filters are bound to interfaces - physical and
virtual. If a virtual interface is created, the rules attached to the real interface is
copied to the ruleset for the virtual interface. This can be modified. In the packet
filter sequence, only the virtual interface ruleset will be used for the packets exiting
from a virtual interface. The physical interface rules will have no effect on these
packets.
•
In contrast to other products, OA-700 differentiates between the classification and
the actions. The classification on OA-700 is done by the use of match-lists and the
actions are done by the use of filters.
•
Our product is not a “
pure
” firewall appliance. In fact, it is an unified device of
routing, Firewall, IDS/IPS, and voice. Firewall is only one component in the
system, and is not enabled by default.
So the “proper installation” to
enable
firewall is for you to create a default ACL policy, and bind it to untrusted interfaces
to deny all traffic, such as the following commands:
Содержание OmniAccess 700
Страница 38: ...Left running head Chapter name automatic 12 Beta Beta CLI Configuration Guide Alcatel Lucent ...
Страница 176: ...Left running head Chapter name automatic 150 Beta Beta CLI Configuration Guide Alcatel Lucent ...
Страница 224: ...Per VLAN Spanning Tree Left running head Chapter name automatic 198 Beta Beta CLI Configuration Guide Alcatel Lucent ...
Страница 258: ...Port Monitoring Left running head Chapter name automatic 232 Beta Beta CLI Configuration Guide Alcatel Lucent ...
Страница 260: ...Left running head Chapter name automatic 234 Beta Beta CLI Configuration Guide Alcatel Lucent ...
Страница 296: ...T1E1 Line Card Left running head Chapter name automatic 270 Beta Beta CLI Configuration Guide Alcatel Lucent ...
Страница 360: ...Point to Point Protocol Left running head Chapter name automatic 334 Beta Beta CLI Configuration Guide Alcatel Lucent ...
Страница 434: ...Left running head Chapter name automatic 408 Beta Beta CLI Configuration Guide Alcatel Lucent ...
Страница 462: ...Common Classifiers Left running head Chapter name automatic 436 Beta Beta CLI Configuration Guide Alcatel Lucent ...
Страница 464: ...Left running head Chapter name automatic 438 Beta Beta CLI Configuration Guide Alcatel Lucent ...
Страница 534: ...Border Gateway Protocol Left running head Chapter name automatic 508 Beta Beta CLI Configuration Guide Alcatel Lucent ...
Страница 638: ...Left running head Chapter name automatic 612 Beta Beta CLI Configuration Guide Alcatel Lucent ...
Страница 762: ...Filter and Firewall Left running head Chapter name automatic 736 Beta Beta CLI Configuration Guide Alcatel Lucent ...
Страница 890: ...Transparent Firewall Left running head Chapter name automatic 864 Beta Beta CLI Configuration Guide Alcatel Lucent ...
Страница 940: ...Left running head Chapter name automatic 914 Beta Beta CLI Configuration Guide Alcatel Lucent ...
Страница 1000: ...Quality of Service Left running head Chapter name automatic 974 Beta Beta CLI Configuration Guide Alcatel Lucent ...
Страница 1002: ...Left running head Chapter name automatic 976 Beta Beta CLI Configuration Guide Alcatel Lucent ...
Страница 1044: ...DNS Domain Name Service Client Left running head Chapter name automatic 1018 Beta Beta CLI Configuration Guide Alcatel Lucent ...
Страница 1046: ...Left running head Chapter name automatic 1020 Beta Beta CLI Configuration Guide Alcatel Lucent ...
Страница 1058: ...Left running head Chapter name automatic 1032 Beta Beta CLI Configuration Guide Alcatel Lucent ...
Страница 1074: ...Lifeline Left running head Chapter name automatic 1048 Beta Beta CLI Configuration Guide Alcatel Lucent line con 0 end ...
Страница 1076: ...Left running head Chapter name automatic 1050 Beta Beta CLI Configuration Guide Alcatel Lucent ...
Страница 1118: ...Web Cache Server Left running head Chapter name automatic 1092 Beta Beta CLI Configuration Guide Alcatel Lucent ...
Страница 1120: ...Left running head Chapter name automatic 2 Beta Beta CLI Configuration Guide Alcatel Lucent ...
Страница 1140: ...QoS Values and Mnemonics Left running head Chapter name automatic 22 Beta Beta CLI Configuration Guide Alcatel Lucent ...
Страница 1156: ...IPsec Interoperability of OA 700 Left running head Chapter name automatic 38 Beta Beta CLI Configuration Guide Alcatel Lucent ...