Resource Groups
determine if a packet should be dropped or passed through the Bandura
Cyber TIG. A Resource Group filters internet traffic traveling in one direction:
● Inbound:
filters traffic entering your network
● Outbound:
filters traffic leaving your network
A resource group includes a list of
Resources
, which lists internet addresses within your
network. These lists operate slightly different, depending on the direction of the resource group:
● Inbound:
rules identify what services your local computers offer to the internet
● Outbound:
rules identify what services your local computers can access on the internet
When you plan your Bandura Cyber TIG configuration, first determine what services or protocols
you want to expose to the world, and which machines will offer these services. You can also
determine what services and protocols you want your local machine to access. You can create
numerous resource groups corresponding to various classes of machines.
Example: Your office computers may need only web and email access, and no outside
computer should be able to access them for any reason. Your web and email services need to
expose their services to the internet, which your router will need to query outside domain name
servers.
You can configure custom resource groups to cover all the above circumstances. When you
explicitly allow only particular services, you close large numbers of network protocol backdoors
that could otherwise be used by intruders.
There are two resource groups on the Bandura Cyber TIG that cannot be deleted. The
DEFAULT_INBOUND
and
DEFAULT_OUTBOUND
are applied to any packet containing a local
internet address that cannot be found in a custom resource group.
2.6 Configuring a Resource Group
Resource groups filter traffic flowing through the Bandura Cyber TIG, with each particular
resource group filtering either inbound or outbound traffic. Examine your local network,
considering your security needs as well as the internet services you need to offer to the world,
and those you need to access.
A new Bandura Cyber TIG allows all traffic to and from the internet. Any internet address within
your network, unless blocked, will be allowed.
Resource groups contain the following parts:
● Direction:
resource group either filters inbound or outbound
● Resources:
list of external internet addresses and countries to allow or block
20