已阅读5页,还剩26页未读, 继续免费阅读
版权说明:本文档由用户提供并上传,收益归属内容提供方,若内容存在侵权,请进行举报或认领
文档简介
CiscoIOSThreatDefenseFeatures,IntroducingtheCiscoIOSFirewall,LayeredDefenseStrategy,DMZ,ADMZisestablishedbetweensecurityzonesDMZsarebuffernetworkswhichareneitherinsidenoroutside.,LayeredDefenseFeatures,Accesscontrolisenforcedontrafficenteringandexitingthebuffernetworktoallsecurityzonesby:ClassicroutersDedicatedfirewallsDMZsareusedtohostservices:Exposedpublicservicesareservedondedicatedhostsinsidethebuffernetwork.TheDMZmayhostanapplicationgatewayforoutboundconnectivity.ADMZcontainsanattackerinthecaseofabreak-in.ADMZisthemostusefulandcommonmodernarchitecture.,MultipleDMZs,MultipleDMZsprovidebetterseparationandaccesscontrol:EachservicecanbehostedinitsownDMZ.Damageislimitedandattackerscontainedifaserviceiscompromised.,ModernDMZDesign,Varioussystems(statefulpacketfilter,proxyserver)canfiltertraffic.Properconfigurationofthefilteringdeviceiscritical.,FirewallTechnologies,FirewallTechnologies,Firewallsusethreetechnologies:PacketfilteringApplicationlayergatewayStatefulpacketfiltering,PacketFiltering,Packetfilteringlimitstrafficintoanetworkbasedonthedestinationandsourceaddresses,ports,andotherflagscompiledinanACL.,PacketFilteringExample,Router(config)#access-list100permittcpany55establishedRouter(config)#access-list100denyipanyanylogRouter(config)#interfaceSerial0/0Router(config-if)#ipaccess-group100inRouter(config-if)#end,ApplicationLayerGateway,TheALGinterceptsandestablishesconnectionstotheInternethostsonbehalfoftheclient.,ALGFirewallDevice,StatefulPacketFiltering,StatelessACLsfiltertrafficbasedonsourceanddestinationIPaddresses,TCPandUDPportnumbers,TCPflags,ICMPtypesandcodes.Statefulinspectionthenrememberscertaindetails,orthestateofthatrequest.,StatefulFirewallOperation,StatefulFirewalls,Alsocalled“Statefulpacketfilters”and“Application-awarepacketfilters.”Statefulfirewallshavetwomainimprovementsoverpacketfilters:Theymaintainasessiontable(statetable),wheretheytrackallconnections.Theyrecognizedynamicapplicationsandknowwhichadditionalconnectionswillbeinitiatedbetweentheendpoints.Statefulfirewallsinspecteverypacket,compareitagainstthestatetable,andmayexaminethepacketforanyspecialprotocolnegotiations.Statefulfirewallsoperatemainlyattheconnection(TCPandUDP)layer.,StatefulFirewallHandlingofDifferentProtocols,IntroducingtheCiscoIOSFirewallFeatureSet,TheCiscoIOSFirewallFeatureSet,TheCiscoIOSFirewallFeatureSetcontainsthreemainfeatures:CiscoIOSFirewallAuthenticationproxyIPS,CiscoIOSFirewall,PacketsareinspectedenteringtheCiscoIOSfirewalliftheyarenotspecificallydeniedbyanACL.CiscoIOSFirewallpermitsordeniesspecifiedTCPandUDPtrafficthroughafirewall.Astatetableismaintainedwithsessioninformation.ACLsaredynamicallycreatedordeleted.CiscoIOSFirewallprotectsagainstDoSattacks.,CiscoIOSAuthenticationProxy,HTTP,HTTPS,FTP,andTelnetauthenticationProvidesdynamic,per-userauthenticationandauthorizationviaTACACS+andRADIUSprotocols,CiscoIOSIPS,ActsasaninlineintrusionpreventionsensortrafficgoesthroughthesensorWhenanattackisdetected,thesensorcanperformanyoftheseactions:Alarm:SendanalarmtoSDMorsyslogserver.Drop:Dropthepacket.Reset:SendTCPresetstoterminatethesession.Block:BlockanattackerIPaddressorsessionforaspecifiedtime.Identifies700+commonattacks,CiscoIOSFirewallFunctions,CiscoIOSACLsRevisited,ACLsprovidetrafficfilteringbythesecriteria:SourceanddestinationIPaddressesSourceanddestinationportsACLscanbeusedtoimplementafilteringfirewallleadingtothesesecurityshortcomings:Portsopenedpermanentlytoallowtraffic,creatingasecurityvulnerabilityDonotworkwithapplicationsthatnegotiateportsdynamicallyCiscoIOSFirewalladdressestheseshortcomingsofACLs.,CiscoIOSFirewallTCPHandling,CiscoIOSFirewallUDPHandling,CiscoIOSFirewallProcess,HowCiscoIOSFirewallWorks,SupportedProtocols,TCP(singlechannel)UDP(singlechannel)RPCFTP/FTPSTFTPTelnet/SSHUNIXR-commands(suchasrlogin,rexec,andrsh)SMTPHTTP/HTTPSICMPSNMPKazaa,SQL*NetRTSP(suchasRealNetworks)Tacacs+/RadiusSignallingH.323SkinnySIPOthermultimedia:MicrosoftNetShowStreamWorksVDOLiveBGPAndmanyothers,AlertsandAuditTrails,CiscoIOSFirewallgeneratesreal-timealertsandaudittrails.Audittrailfeaturesusesyslogtotrackallnetworktransactions.WithCiscoIOSFirewallinspectionrules,youcanconfigurealertsandaudittrailinformationonaper-applicationprotocolbasis.,Summary,Layereddefensestrategyenhancessecuritybyprovidingbuffernetworkswithfilteringcapabilities.Therearethreemainfirewalltechnologies:packetfiltering,applicationproxy,andstatefulpacketfiltering.TheCiscoIOSFeatureSetcontainsthreemainfeatures:CiscoIOSFirewall,authenticationproxy,andIPS.CiscoIOSFirewallintelligentlyfiltersTCP
温馨提示
- 1. 本站所有资源如无特殊说明,都需要本地电脑安装OFFICE2007和PDF阅读器。图纸软件为CAD,CAXA,PROE,UG,SolidWorks等.压缩文件请下载最新的WinRAR软件解压。
- 2. 本站的文档不包含任何第三方提供的附件图纸等,如果需要附件,请联系上传者。文件的所有权益归上传用户所有。
- 3. 本站RAR压缩包中若带图纸,网页内容里面会有图纸预览,若没有图纸预览就没有图纸。
- 4. 未经权益所有人同意不得将文件中的内容挪作商业或盈利用途。
- 5. 人人文库网仅提供信息存储空间,仅对用户上传内容的表现方式做保护处理,对用户上传分享的文档内容本身不做任何修改或编辑,并不能对任何下载内容负责。
- 6. 下载文件中如有侵权或不适当内容,请与我们联系,我们立即纠正。
- 7. 本站不保证下载资源的准确性、安全性和完整性, 同时也不承担用户因使用这些下载资源对自己和他人造成任何形式的伤害或损失。
最新文档
- 财务报表制作及审核管理模板
- 2023年度职称评审申报资料模板指南
- 企业财务报表自动化处理模板
- 二年级上册数学教案第七单元第1课时 乘法和除法的意义-西师大版
- 小学心理健康教育管理标准方案
- 高密度场所消防安全管理办法
- 2025进口食品行业市场发展分析及前景预测与投资价值研究报告
- 2025边缘计算在智能交通系统中的实际应用与投资回报分析报告
- 2025跨境支付系统优化研究及区块链技术应用评估报告
- 北师大版八年级上册3 勾股定理的应用教案
- CJ/T 94-2005饮用净水水质标准
- 水稳层施工工艺流程及质量控制措施
- ICU患者体位管理
- 2025春季学期国开河南电大本科补修课《汉语基础#》一平台无纸化考试(作业练习+我要考试)试题及答案
- 2025-2030年中国铝合金游艇行业市场调研与发展前景预测研究报告
- 小产权房子赠予合同协议
- 《合同法与建筑工程》课件
- 护理意外事件应急预案
- 术中急性大出血应急演练方案
- 公路工程施工监理合同范本
- 环境友好高分子-深度研究
评论
0/150
提交评论