Re: [fw-wiz] Auditing a firewall rulebase



If its an external firewall then you can check to make sure that bogon
lists are being filtered. In addition check to make sure that
internal ip space is being denied as the source coming from anywhere
else. Make sure denied rule hits are being logged. Also check for
ports and protocols that should be denied such as telnet, 1433,
finger, etc inbound.

On Wed, May 14, 2008 at 11:19 AM, arvind doraiswamy
<arvind.doraiswamy@xxxxxxxxx> wrote:
Hey Guys,
What parameters would you look for if you audited a large rulebase for
an enterprise firewall? These are a few I could think of. Anything
else that you guys consistently look at when managing/auditing your
firewalls? Do take note that I'm talking just singularly about the
rule-base and not other configuration information i.e: I'm not looking
at things like -- Low console session timeout OR Telnet admin
interface open etc. I'm looking at just the rulebase this time around.
Here are my parameters:

Rules which have "any" or an equivalent keyword in them
Rules where an entire subnet has been granted access to a resource
Rules where a range of IP addresses has been granted access to a resource
Rules where a large range of ports has been opened to an IP Address / Addresses
Rules where there are design issues in the protocol itself
eg. Unencrypted traffic
Rules which are redundant and can be removed from the rulebase

Thanks
Arvind
_______________________________________________
firewall-wizards mailing list
firewall-wizards@xxxxxxxxxxxxxxxxxxxxx
https://listserv.icsalabs.com/mailman/listinfo/firewall-wizards

_______________________________________________
firewall-wizards mailing list
firewall-wizards@xxxxxxxxxxxxxxxxxxxxx
https://listserv.icsalabs.com/mailman/listinfo/firewall-wizards



Relevant Pages

  • [fw-wiz] Auditing a firewall rulebase
    ... an enterprise firewall? ... interface open etc. I'm looking at just the rulebase this time around. ... Rules where a range of IP addresses has been granted access to a resource ...
    (Firewall-Wizards)
  • Re: Firewall rulebase automation - Grey Box assessment
    ... expansion of the object group both the rules are exactly the same ... primarily targets any rules in the rulebase and not other "logically" ... I tried to make this look at a firewall a bit mor ... I can add support for as MANY firewalls as I want ...
    (Pen-Test)
  • Re: Firewall rulebase automation - Grey Box assessment
    ... Does the tool identifies conflicting rules which is often time one of the main concern with a very large rulebase. ... Maybe there have been times when you have pentested a firewall. ... Securing Web Applications ... Get 45 Min Video and PPT Slides ...
    (Pen-Test)
  • Re: [fw-wiz] Auditing a firewall rulebase
    ... interface open etc. I'm looking at just the rulebase this time around. ... Rules where a range of IP addresses has been granted access to a resource ... Look for rules that you do not have a written justification for; if a rule is for a single application or user group, ask if it is still justified. ...
    (Firewall-Wizards)
  • Re: [fw-wiz] Auditing a firewall rulebase
    ... -Make sure all rules are performance-based, e.g. most hit rule first in line, etc. to cut down on cpu and bandwidth. ... interface open etc. I'm looking at just the rulebase this time around. ... Rules where a range of IP addresses has been granted access to a resource ...
    (Firewall-Wizards)