Security
7-29
Basic Firewall’s filters play the following roles.
Input filters 1 and 2:
These block WAN-originated OpenWindows and
X-Windows sessions. Ser vice origination requests for these protocols
use por ts 2000 and 6000, respectively. Since these are greater than
1023, OpenWindows and X-Windows traffic would other wise be
allowed by input filter 4. Input filters 1 and 2 must precede input filter
4; other wise they would have no effect as filter 4 would have already
passed OpenWindows and X-Windows traffic.
Input filter 3:
This filter explicitly passes all WAN-originated ICMP
traffic to permit devices on the WAN to ping devices on the LAN. Ping
is an Internet ser vice that is useful for diagnostic purposes.
Input filters 4 and 5:
These filters pass all TCP and UDP traffic,
respectively, when the destination por t is greater than 1023. This type
of traffic generally does not allow a remote host to connect to the LAN
using one of the potentially intrusive Internet ser vices, such as Telnet,
FTP, and WWW.
Output filter 1:
This filter passes all outgoing traffic to make sure that
no outgoing connections from the LAN are blocked.
Basic Firewall is suitable for a LAN containing only client hosts that
wish to access ser vers on the WAN, not for a LAN containing ser vers
providing ser vices to clients on the WAN. Basic Firewall’s general
strategy is to explicitly pass WAN-originated TCP and UDP traffic to
por ts greater than 1023. Por ts lower than 1024 are the ser vice
origination por ts for various Internet ser vices such as FTP, Telnet, and
the World Wide Web (WWW).
A more complicated filter set would be required to provide WAN
access to a LAN-based ser ver. See
“Possible modifications,”
below,
for ways to allow remote hosts to use ser vices provided by ser vers on
the LAN.
Possible modifications
You can modify the sample filter set Basic Firewall to allow incoming
traffic using the examples below. These modifications are not
intended to be combined. Each modification is to be the only one used
with Basic Firewall.
Содержание 430 S/T
Страница 1: ...Netopia ISDN Router Reference Guide F on arall Farallon Communications Inc...
Страница 133: ...6 20 Netopia ISDN Router Reference Guide...
Страница 173: ...8 8 Netopia ISDN Router Reference Guide...
Страница 192: ...Monitoring Tools 9 19...
Страница 193: ...9 20 Netopia ISDN Router Reference Guide...
Страница 255: ...F 2 Netopia ISDN Router Reference Guide...
Страница 276: ......