rozsirim![]()
Action Protocol Source Destination Port Description
Deny IP 10.0.0.0/8 Any Any RFC 1918 Private Network
Deny IP 192.168.0.0/16 Any Any RFC 1918 Private Network
Deny IP 172.16.0.0/12 Any Any RFC 1918 Private Network
Deny IP DMZ subnet Any Any DMZ network
Deny IP 127.0.0.0/8 Any Any Loopback Network
Deny IP 0.0.0.0/8 Any Any Historic Broadcast
Deny IP 224.0.0.0/4 Any Any Class D Multicast
Deny IP 240.0.0.0/5 Any Any Class E Multicast
Deny IP 248.0.0.0/5 Any Any Unallocated
Deny IP 255.255.255.255/32 Any Any Broadcast
Deny IP Any router ip Any Drop all traffic destined to the router
Deny TCP Any Any 135-139, 445 MS ports
Deny UDP Any Any 135-139, 445 MS ports
Deny TCP Any Any 23, 111, 512 -514, 2049, 6000-6063 Unix Ports
Deny UDP Any Any 111, 2049, 6000-6063 Unix Ports
Deny UDP Any Any 69, 161, 162, 514 SNMP, syslog, TFTP
Permit IP Any DMZ NET Any Allow access to DMZ
Permit IP Any NAT addresses Any Allow access to NAT address of DMZ FW
Deny IP Any Any Any Drop all other traffic
tohle je takova zakladni sablona pro prichozi interface na border routru, samozrejme co je potreba se pripadne povoli...
stejne tak existuje sablona pro vnitrni interface na routru...
koho to zajima vice viz www.sans.org
pripadne prakticky priklad z ktereho jsem si ten kousek vzal...http://www.sans.org/reading_room/whi...lyst_gcfw_1621