Selecting Services for your Security Policy Objectives
User Guide
115
•
Services that send passwords in the clear (FTP, telnet,
POP) are very risky.
•
Services with built-in strong authentication (such as
ssh) are reasonably safe. If the service does not have
built-in authentication, you can mitigate the risk by
using user authentication with that service.
•
Services such as DNS, SMTP, anonymous FTP, and
HTTP are safe only if they are used in their intended
manner.
•
Allowing a service to access only a single internal host
is safer than allowing the service to access several or all
hosts.
•
Allowing a service from a restricted set of hosts is
somewhat safer than allowing the service from
anywhere.
•
Allowing a service to the optional network is safer than
allowing it to the trusted network.
•
Allowing incoming services from a virtual private
network (VPN), where the organization at the other
end is known and authenticated, is generally safer than
allowing incoming services from the Internet at large.
Each safety precaution you implement makes your net-
work significantly safer. Following three or four precau-
tions is much safer than following one or none.
Outgoing service guidelines
In general, the greatest risks come from incoming services,
not outgoing services. There are, however, some security
risks with outgoing services as well. Control of outgoing
services helps to protect your network from hostile acts
within your organization. For example, when configuring
the outgoing FTP service, you can make it read-only and/
or restrict the destination hosts that can receive such a
transmission. This prevents insiders from using FTP to
transmit corporate secrets to a home computer or to a rival
organization.
Содержание Firebox X1000
Страница 1: ...WatchGuard Firebox System User Guide WatchGuard Firebox System...
Страница 12: ...xii WatchGuard Firebox System...
Страница 44: ...Chapter 2 Service and Support 22 WatchGuard Firebox System...
Страница 61: ...Cabling the Firebox User Guide 39...
Страница 68: ...Chapter 3 Getting Started 46 WatchGuard Firebox System...
Страница 78: ...Chapter 4 Firebox Basics 56 WatchGuard Firebox System...
Страница 156: ...Chapter 8 Configuring Filtered Services 134 WatchGuard Firebox System...
Страница 182: ...Chapter 9 Configuring Proxied Services 160 WatchGuard Firebox System...
Страница 220: ...Chapter 11 Intrusion Detection and Prevention 198 WatchGuard Firebox System...
Страница 242: ...Chapter 12 Setting Up Logging and Notification 220 WatchGuard Firebox System...
Страница 255: ...Working with Log Files User Guide 233 appear until the remote office Firebox has been properly configured...
Страница 256: ...Chapter 13 Reviewing and Working with Log Files 234 WatchGuard Firebox System...
Страница 274: ...Chapter 14 Generating Reports of Network Activity 252 WatchGuard Firebox System...