Do not use on any
shared computer
August 21, 2008 07:27pm pdt
 
[x]
Attachment Details

help with Netscreen Policies/Screening

Tags: netscreen, firewall, security, ports, router
Hi, I'm looking for advice on what policies i need and what screening to turn on for a Netscreen 5xp device (or Netscreens in general). Can you please confirm or refute my beliefs below and provide explanations? My network setup is very simple--one MS SBS2003 server running Exchange 2003 with 10 XP clients using one Netscreen 5xp as gateway/firewall. I'm only using trust and untrust virtual routers.

1) I only need to make "Allow" policies? All other traffic is denied by default?

Trust->Untrust to allow outbound traffic for LAN users and Server. All I need to allow on Trust-Untrust are network protocols needed: Blackberry Ent. Server, DNS, FTP, HTTP, HTTPS, ICMP-ANY, IMAP, MAIL, PING, POP3, SSH
am I missing any common protocols? i think i have all the common ones

Untrust->Trust to allow Exchange server to work: HTTP, SMTP, PING

So, I only need these two "Allow" policies. I don't need any "Deny" policies since anything other than these port openings are by default denied anyway??

2) Screening??

Trust Zone Screening: I check all Screening options for Trust zone except for "Block HTTP Components" section (I want to allow users to download Java apps, .exe files, etc.). Is this correct? Any reason to NOT check off everything in Trust Zone?

Untrust zone screening: I left only the default screening options checked for the Untrust zone:
SYN Flood Protection
Ping of Death Attack Protection
Land Attack Protection
IP Source Route Option Filter
**Should I check off everything in Untrust Zone or just leave these defaults? Why are these defaults?

So, that's all i have set up right now. Two "Allow" policies and screening as stated above. Any suggestions much appreciated.

Start your free trial to view this solution
Question Stats
Zone: Security
Question Asked By: goldylamont
Question Asked On: 07.23.2008
Participating Experts: 1
Points: 500
Views: 0
Translate:
Loading Advertisement...
 
[+][-]Expert Comment by Qlemo
Expert Comment by Qlemo:

All comments and solutions are available to Premium Service Members only.

Start your 7-day free trial and see for yourself why Experts Exchange is the easiest and most proven technology resource in the world. Get Started

Already a member? Login to view this solution.

 
 
[+][-]Author Comment by goldylamont
Author Comment by goldylamont:

All comments and solutions are available to Premium Service Members only.

Start your 7-day free trial and see for yourself why Experts Exchange is the easiest and most proven technology resource in the world. Get Started

Already a member? Login to view this solution.

 
 
[+][-]Expert Comment by Qlemo
Expert Comment by Qlemo:

All comments and solutions are available to Premium Service Members only.

Start your 7-day free trial and see for yourself why Experts Exchange is the easiest and most proven technology resource in the world. Get Started

Already a member? Login to view this solution.

 
 
Loading Advertisement...
20080723-EE-VQP-34 / EE_QW_EXPERT_20070906