Firewall Policy

Firewall Policy

Secure Home | Search | About
 Networking Firewalls    Post an article   get this group's latest topics as an RSS feed add this group's latest topics to your My MSN content add this group's latest topics to your My Yahoo content add this group's latest topics to your Google content
Subject Author Date
Firewall Policy mhyasseen 03-31-2008
---> Re: Firewall Policy Ansgar -59cobal...03-31-2008
Posted by on March 31, 2008, 8:41 am
If you were  Registered and logged in, you could reply and use other advanced thread options
Hi
I am an undergraduate student. I have a project related to the
firewall policy. Although I have got some material, I required some
more reference regarding the following topics. Any help would be
appreciated.
(1) What will be size of the firewall policy for an enterprise
network.
(2) What rules in general contain in the rule set i.e., accept. or
deny
(3) What are rules which are at the top of the rule set and which one
are the end of the rule set,
(4) and why the rules at the bottom of the ruleset have the lowest
priority than the rules at the top of the ruleset.

Yaseen

Posted by Ansgar -59cobalt- Wiechers on March 31, 2008, 11:02 am
If you were  Registered and logged in, you could reply and use other advanced thread options
mhyasseen@gmail.com wrote:
> I am an undergraduate student. I have a project related to the
> firewall policy. Although I have got some material, I required some
> more reference regarding the following topics. Any help would be
> appreciated.
> (1) What will be size of the firewall policy for an enterprise
> network.

This question doesn't make any sense. What do you mean by "size of the
firewall policy"?

> (2) What rules in general contain in the rule set i.e., accept. or
> deny

Both.

> (3) What are rules which are at the top of the rule set and which one
> are the end of the rule set,

That entirely depends on your particular requirements. Firewalls don't
come as "one size fits all" solutions.

> (4) and why the rules at the bottom of the ruleset have the lowest
> priority than the rules at the top of the ruleset.

Because the rules on top match first (normally, that is).

Read a good book on firewalls (e.g. [1]), and make sure you have at
least a basic understanding of networking before you do.

[1] http://www.oreilly.com/catalog/fire2/

cu
59cobalt
--
"If a software developer ever believes a rootkit is a necessary part of
their architecture they should go back and re-architect their solution."
--Mark Russinovich

Posted by Juergen Nieveler on March 31, 2008, 2:45 pm
If you were  Registered and logged in, you could reply and use other advanced thread options

>> (3) What are rules which are at the top of the rule set and which one
>> are the end of the rule set,
>
> That entirely depends on your particular requirements. Firewalls don't
> come as "one size fits all" solutions.

Although usually, the lowest rule of the ruleset will be "Reject all".

Juergen Nieveler
--
Bud said, "Let there be lite" and there was Lite

Posted by jc on April 1, 2008, 3:45 am
If you were  Registered and logged in, you could reply and use other advanced thread options
Juergen Nieveler a écrit :
>
>
>>.....
>
>
> Although usually, the lowest rule of the ruleset

will be

Best HAVE TO BE
"Reject all".
>
> Juergen Nieveler


Posted by Jens Hoffmann on March 31, 2008, 2:39 pm
If you were  Registered and logged in, you could reply and use other advanced thread options

> (1) What will be size of the firewall policy for an enterprise
> network.

Depends on the needs of the specific enterprise.
Can be between 1 or 2 rules to hundreds of rules and a couple of firewalls
with different rules each.

> (2) What rules in general contain in the rule set i.e., accept. or
> deny

A sensible decision would be to deny any communication which is not
explicitly allowed and wanted.

> (3) What are rules which are at the top of the rule set and which one
> are the end of the rule set,

You are implying a precedence in ordering the rules, which might not
be present in all firewalls.

> (4) and why the rules at the bottom of the ruleset have the lowest
> priority than the rules at the top of the ruleset.

Many firewalls only process the rules top to bottom until they
find a match and then stop processing.

Again, this might not be true for all firewalls.

I personally like: ISBN-13: 978-0201634662 as an introductional book.

Cheers,
Jens

Similar ThreadsPosted
Firewall Policy Mgt? June 14, 2006, 4:18 pm
Netscreen firewall policy April 25, 2005, 10:46 am
How to backup firewall policy package on CheckPoint Express NG? April 22, 2005, 7:45 am
Symantec Client Security 3.0 - Firewall Policy Update Failed April 28, 2006, 10:43 am
Please help me find a way to backup/restore firewall policy package on CheckPoint Express April 19, 2005, 8:59 pm
Netscreen CLI (edit policy) April 26, 2006, 4:51 pm
Question about netscreen set policy June 22, 2007, 3:14 pm
https inbound policy NS-25? June 5, 2008, 12:43 am
Zonelab's intimidating upgrade policy March 19, 2005, 3:24 am
WatchGuard FireBox v60 - Security Policy June 20, 2005, 12:19 pm

The site map in XML format XML site map

Contact Us | Privacy Policy