Configuring Filters
9-13
Example Filters
Rule to Allow Authentication Queries
To allow authentication queries used by some mailers and FTP servers, add the following
rule to your input filter:
Command>
set filter
filtername RuleNumber
permit tcp dst eq 113
For more information about these types of queries, refer to RFC 1413.
Rule to Allow Networks Full Access
To allow some other network to have complete access to your network, add the
following rule. In the example below, 172.16.12.0 is granted full access to
192.168.1.0/24:
Command>
set filter
filtername RuleNumber
permit 172.16.12.0/24 192.168.1.0/24
Caution –
Beware of associative trust. If you allow a network complete access to your
network, you might unknowingly allow other networks complete access, as well. Any
network that can access a network having complete access privileges to your network,
also has access to your network. For example, if Network 1 trusts Network 2 and
Network 2 trusts Network 3, then Network 1 trusts Network 3.
Restrictive Internet Filter
This example filter allows any kind of outgoing connection from the server, but blocks
all incoming traffic to any host but your designated Internet server. This filter also limits
incoming traffic on your Internet server to: SMTP, Network News Transfer Protocol
(NNTP), DNS, FTP, and ICMP services.
Note –
Even if you have the latest versions of the daemons
ftpd
,
httpd
, and
sendmail
you may be vulnerable to attacks through these services. Check the latest CERT
Coordination Center advisories, available on
ftp.cert.org
, for the vulnerabilities of these
services.
!
✍
Содержание PortMaster
Страница 16: ...Contents xvi Configuration Guide for PortMaster Products...
Страница 26: ...Subscribing to PortMaster Mailing Lists xxvi PortMaster Configuration Guide...
Страница 32: ...Basic Configuration Steps 1 6 PortMaster Configuration Guide...
Страница 114: ...Configuring WAN Port Settings 6 12 PortMaster Configuration Guide...
Страница 128: ...Configuring Login Users 7 14 PortMaster Configuration Guide...
Страница 158: ...Restricting User Access 9 16 PortMaster Configuration Guide...
Страница 168: ...Configuring Ports for Modem Use 10 10 PortMaster Configuration Guide...
Страница 222: ...Frame Relay Subinterfaces 13 16 PortMaster Configuration Guide...
Страница 236: ...Troubleshooting a Synchronous V 25bis Connection 14 14 PortMaster Configuration Guide...
Страница 252: ...Using ISDN for On Demand Connections 15 16 PortMaster Configuration Guide...
Страница 264: ...Using ISDN for Internet Connections 16 12 PortMaster Configuration Guide...
Страница 276: ...Configuration Steps for Dial In Access 17 12 PortMaster Configuration Guide...
Страница 286: ...Configuration Steps for Shared Device Access 18 10 PortMaster Configuration Guide...
Страница 296: ...Troubleshooting a Leased Line Connection 19 10 PortMaster Configuration Guide...
Страница 310: ...B 4 PortMaster Configuration Guide...
Страница 352: ...Command Index Command Index 6 PortMaster Configuration Guide...