Re: Writing firewall ruleserts ... Recommend good procedure and resource for ports lookup?

From: Devdas Bhagat (dvb_at_users.sourceforge.net)
Date: 05/15/03

  • Next message: Wayne Maples: "RE: [tech] Decrypt File"
    Date: Fri, 16 May 2003 00:22:48 +0530
    To: security-basics@securityfocus.com
    
    

    On 14/05/03 22:02 +0100, Mark (fat) wrote:
    > I have to write firewall rulesets for a pair of back to back dual vendor
    > firewalls with multiple DMZ's from each.
    >
    > Can anyone recommend a good procedure to use. Opensource would be great
    > but you cant really beat a good book.
    Standard rules:
    Default everything to closed and see what breaks, open ports as
    required. "Building Internet Firewalls" (O'Reilly and Associates) is a
    good book to start with.

    > Also can anyone recommend a good resource for translating services into
    > ports etc
    grep portnumber /etc/services

    Devdas Bhagat

    ---------------------------------------------------------------------------
    Thinking About Security Training? You Can't Afford Not To!

    Vigilar's industry leading curriculum includes: Security +, Check Point,
    Hacking & Assessment, Cisco Security, Wireless Security & more! Register Now!
    --UP TO 30% off classes in select cities--
    http://www.securityfocus.com/Vigilar-security-basics
    ----------------------------------------------------------------------------


  • Next message: Wayne Maples: "RE: [tech] Decrypt File"

    Relevant Pages

    • Re: Defense in Depth
      ... What is meant by "layers" of security, is this: the entry points that must be ... Physical Layer - Physical access to the resources. ... attacks and other attacks that go after the software itself. ... "layer" in one long chain (lots of firewalls). ...
      (Security-Basics)
    • RE: Wireless Security for Home Users
      ... for most home users to create and/or manage 2 firewalls and a DMZ. ... As with most network security, ... investigate additional security features available from the WAP ...
      (Security-Basics)
    • RE: [Full-Disclosure] RE: MS SQL WORM IS DESTROYING INTERNET BLOCK PORT 1434!
      ... > 1) I don't trust MS products for security related tasks. ... firewalls running on NT? ... necessary steps to mitigate the risk and protect yourself. ... We still had six boxes hit. ...
      (Full-Disclosure)
    • RE: IDS is dead, etc
      ... Most firewall logs are just as tough to decipher as IDSs. ... Automated security analytics is a tough animal I don't care what the system. ... firewalls and IDSs, not just IDSs. ... There is no solution to these problems, therefore IDS is dead and we ...
      (Focus-IDS)
    • RE: [Full-Disclosure] Re: Microsoft Security, baby steps ?
      ... You can have firewalls guarding the outside, ... the network? ... We also need software vendors to ... stop giving lip service to security and start actually implementing it. ...
      (Full-Disclosure)