Alteon Application Switch Operating System Application Guide
Filtering and Traffic Manipulation
Document ID: RDWR-ALOS-V2900_AG1302
379
Filter-Based Security
This section includes an example for configuring filters for providing the best security. Radware
recommends that you configure filters to deny all traffic except for those services that you
specifically want to allow. Consider the example network in
Figure 59 - Filter-Based Security
Configuration Example, page 379
Figure 59: Filter-Based Security Configuration Example
In this example, the network is made of local clients on a collector Alteon, a Web server, a mail
server, a domain name server, and a connection to the Internet. All the local devices are on the
same subnet. The administrator wants to install basic security filters to allow only the following
traffic:
•
External HTTP access to the local Web server
•
External SMTP (mail) access to the local mail server
•
Local clients browsing the World Wide Web
•
Local clients using Telnet to access sites outside the intranet
•
DNS traffic
All other traffic is denied and logged by the default filter.
Note:
Since IP address and port information can be manipulated by external sources, filtering does
not replace the necessity for a well-constructed network firewall.
To configure a filter-based security solution
Notes
•
In this example, all filters are applied only to the port that connects to the Internet. If intranet
restrictions are required, filters can be placed on ports connecting to local devices.
Содержание Alteon
Страница 2: ...Alteon Application Switch Operating System Application Guide 2 Document ID RDWR ALOS V2900_AG1302 ...
Страница 42: ...Alteon Application Switch Operating System Application Guide Preface 42 Document ID RDWR ALOS V2900_AG1302 ...
Страница 582: ...Alteon Application Switch Operating System Application Guide High Availability 582 Document ID RDWR ALOS V2900_AG1302 ...