stason.org logo lotus


previous page: 24  Explanation (filtering rules for a kernel-based packet screen)page up: Firewalls FAQnext page: 26  Implementation (filtering rules for a Cisco)

25 What are some reasonable filtering rules for a Cisco?

 Books
 TULARC
















Description

This article is from the Firewalls FAQ, by Matt Curtin cmcurtin@interhack.net and Marcus J. Ranum mjr@nfr.com with numerous contributions by others.

25 What are some reasonable filtering rules for a Cisco?

The example in figure 4 shows one possible configuration for using the
Cisco as filtering router. It is a sample that shows the implementation of
as specific policy. Your policy will undoubtedly vary.

Figure 4: Packet Filtering Router

[\begin{figure} \begin{center} \includegraphics {firewalls-faq4} \end{center}\end{figure}]

In this example, a company has Class C network address 195.55.55.0. Company
network is connected to Internet via IP Service Provider. Company policy is
to allow everybody access to Internet services, so all outgoing connections
are accepted. All incoming connections go through ``mailhost''. Mail and DNS
are only incoming services.

 

Continue to:


Share and Enjoy

Bookmark this story so others can enjoy it:
  • digg
  • Reddit
  • del.icio.us
  • Furl
  • Wists

Tags

security, Internet, firewalls, ssl, port, protection, application layer, proxy server, packet screening, filtering rules, viruses, terms







TOP
previous page: 24  Explanation (filtering rules for a kernel-based packet screen)page up: Firewalls FAQnext page: 26  Implementation (filtering rules for a Cisco)