The Best Damn Firewall Book Period

Shinder, Thomas W

In stock
Regular price 22.250 KD inc. VAT
License
Table of contents
  • Cover
  • Title pagei
  • Copyright Pageiii
  • Contributing Authorsv
  • Contentsxiii
  • Chapter 1: Installing Check Point NGX1
  • Introduction2
  • Preparing the Gateway2
  • Installation2
  • SecurePlatform3
  • FireWall-1/VPN-1 Installation10
  • SmartCenter Server Installation14
  • SmartConsole Installation18
  • Putting It All Together19
  • SmartDashboard19
  • Summary25
  • Chapter 2: SmartDashboard and SmartPortal27
  • Introduction28
  • A Tour of the Dashboard28
  • Logging In28
  • The Rulebase Pane29
  • Security Tab29
  • Address Translation Tab30
  • SmartDefense Tab30
  • Web Intelligence Tab30
  • VPN Manager Tab30
  • QoS Tab30
  • Desktop Security Tab30
  • Web Access Tab30
  • Consolidation Rules Tab31
  • The Objects Tree Pane31
  • Network Objects32
  • Services32
  • Resources32
  • Servers and OPSEC Applications32
  • Users and Administrators32
  • VPN Communities33
  • The Objects List Pane33
  • The SmartMap Pane33
  • Menus and Toolbars33
  • Working with Policy Packages33
  • Installing the Policy34
  • Global Properties34
  • FireWall Page35
  • NAT-Network Address Translation Page35
  • VPN Page35
  • VPN-1 Edge/Embedded Page36
  • Remote Access Page36
  • SmartDirectory (LDAP) Page36
  • Stateful Inspection Page36
  • New in SmartDashboard NGX36
  • Security Policy Rule Names and Unique IDs36
  • Group Object Convention38
  • Group Hierarchy38
  • Clone Object40
  • Session Description40
  • Tooltips40
  • Your First Security Policy41
  • Creating Your Administrator Account43
  • Hooking Up to the Gateway43
  • Reviewing the Gateway Object44
  • Defining Your Security Policy45
  • Policy Design46
  • Creating Rules47
  • Network Address Translation48
  • Installing the Policy49
  • Other Useful Controls on the Dashboard51
  • Working with Security Policy Rules51
  • Section Titles51
  • Hiding Rules51
  • Rule Queries51
  • Searching Rules51
  • Working with Objects51
  • Object References51
  • Who Broke That Object?51
  • Object Queries52
  • Working with Policies52
  • What Would Be Installed?52
  • What's Really Installed?52
  • No Security Please52
  • For the Anoraks52
  • Change Management52
  • Managing Connectra and Interspect Gateways53
  • Configuring Interspect or Connectra Integration53
  • SmartDefense Updates54
  • SmartPortal55
  • SmartPortal Functionality56
  • Installing SmartPortal56
  • Tour of SmartPortal56
  • Summary60
  • Chapter 3: Smart View Tracker61
  • Introduction62
  • Tracker62
  • Log View63
  • Active65
  • Audit66
  • Predefined Queries67
  • Use for Predefined Queries68
  • Adding Custom Queries68
  • Applying Filters69
  • Custom Queries70
  • Matching Rule Filter70
  • Viewing the Matching Rule71
  • Viewing Log Records from SmartDashboard71
  • Active View71
  • Live Connections71
  • Custom Commands72
  • Following a Source or Destination72
  • Block Intruder72
  • Audit View77
  • Log Maintenance78
  • Daily Maintenance78
  • Log Switch80
  • Summary81
  • Chapter 4: SmartDefense and Web Intelligence83
  • Introduction84
  • Network Security84
  • Threats85
  • Structured Threats86
  • Denial of Service86
  • External Threats87
  • Welchia Internet Control Message Protocol88
  • Network Quota88
  • Internal Threats89
  • Reconnaissance (Port Scans and Sweeps)90
  • The OSI Model91
  • Layer 3: The Network Layer92
  • Layer 4: The Transport Layer92
  • Layer 7: The Application Layer93
  • The Need for Granular Inspection94
  • Application Intelligence96
  • Configuring Hosts and Nodes for AI96
  • SmartDefense Technology97
  • Central Configuration and the SmartDefense Web Site98
  • Updating SmartDefense99
  • Defense Against Attacks99
  • Peer-to-Peer99
  • Preventing Information Disclosure100
  • Fingerprint Scrambling101
  • Abnormal Behavior Analysis101
  • Web Intelligence Technology102
  • Malicious Code Protector102
  • Active Streaming102
  • Application Intelligence103
  • Web Application Layer104
  • SQL Injection104
  • Custom Web Blocking105
  • Preventing Information Disclosure106
  • Header Spoofing106
  • Directory Listing107
  • Malicious Code108
  • Definition108
  • Different Types of Malicious Code108
  • General HTTP Worm Catcher109
  • Protocol Inspection110
  • Conformity111
  • DNS Enforcement111
  • HTTP Inspection111
  • Default Configuration112
  • DShield Storm Center113
  • Retrieving Blocklist115
  • Submitting Logs115
  • Summary117
  • Chapter 5: Network Address Translation119
  • Introduction120
  • Global Properties121
  • Network Address Translation122
  • Configuring Dynamic Hide Mode NAT124
  • Dynamic NAT Defined124
  • Advanced Understanding of NAT125
  • When to Use It128
  • Routing and ARP130
  • Adding ARP Entries131
  • Secure Platform131
  • Solaris131
  • Windows132
  • IPSO132
  • Configuring Static Mode NAT132
  • Static NAT Defined133
  • When to Use It133
  • Inbound Connections135
  • Configuring Automatic NAT137
  • When to Use It138
  • NAT Rule Base140
  • Access Control Settings141
  • Configuring Port Translation142
  • When to Use It142
  • NAT Rule Base143
  • Security Policy Implications144
  • Summary145
  • Chapter 6: Authentication147
  • Introduction148
  • Authentication Overview148
  • Using Authentication in Your Environment148
  • Users and Administrators149
  • Managing Users and Administrators149
  • Permission Profiles150
  • Administrators153
  • General Tab153
  • Personal Tab154
  • Groups154
  • Admin Auth154
  • Admin Certificates154
  • Administrator Groups155
  • User Templates156
  • General157
  • Personal157
  • Groups157
  • Authentication157
  • Location157
  • Time158
  • Encryption158
  • User Groups158
  • Users159
  • General160
  • Personal160
  • Groups160
  • Authentication160
  • Location161
  • Time161
  • Certificates161
  • Encryption161
  • External User Profiles161
  • Match by Domain161
  • Match All Users162
  • LDAP Group163
  • Understanding Authentication Schemes163
  • Undefined163
  • SecurID163
  • Check Point Password163
  • RADIUS163
  • TACACS165
  • User Authentication166
  • Configuring User Authentication in the Rulebase166
  • UserAuth Edit Properties General Source167
  • UserAuth Edit Properties General Destination168
  • UserAuth Edit Properties General HTTP168
  • Interacting with User Authentication168
  • Telnet and RLOGIN168
  • FTP169
  • HTTP169
  • Placing Authentication Rules171
  • Advanced Topics172
  • Eliminating the Default Authentication Banner173
  • Changing the Banner173
  • Use Host Header as Destination174
  • Session Authentication175
  • Configuring Session Authentication in the Rulebase176
  • SessionAuth Edit Properties General Source177
  • SessionAuth Edit Properties General Destination177
  • SessionAuth Edit Properties General Contact Agent At177
  • SessionAuth Edit Properties General Accept only SecuRemote/SecureClient Encrypted Connections177
  • SessionAuth Edit Properties General Single Sign-On177
  • Configuring Session Authentication Encryption177
  • The Session Authentication Agent178
  • Configuration Passwords Ask for Password180
  • Configuration Allowed Firewall-1 Allow authentication request from180
  • Configuration Allowed Firewall-1 Options181
  • Interacting with Session Authentication182
  • Client Authentication184
  • Configuring Client Authentication in the Rulebase184
  • ClientAuth Edit Properties General Source185
  • ClientAuth Edit Properties General Destination185
  • ClientAuth Edit Properties General Apply Rule Only if Desktop Configuration Options Are Verifi185
  • ClientAuth Edit Properties General Required Sign-In186
  • ClientAuth Edit Properties General Sign-On Method186
  • Manual Sign-On186
  • Part ially Automatic Sign-O191
  • Fully Automatic Sign-O192
  • Agent Automatic Sign-On192
  • Single Sign-On192
  • General Successful Authentication Tracking192
  • Limits Authorization Timeout193
  • Limits Number of Sessions Allowed193
  • Advanced Topics193
  • Check Point Gateway Authentication194
  • Enabled Authentication Schemes195
  • Authentication Settings195
  • HTTP Security Server195
  • Global Properties Authentication.195
  • Failed Authentication Attempts196
  • Authentication of Users with Certificates196
  • Brute-Force Password Guessing Protection197
  • Early Version Compatibility197
  • Registry Settings197
  • New Interface197
  • Use Host Header as Destination198
  • Opening All Client Authentication Rules198
  • Configuration Files199
  • Enabling Encrypted Authentication199
  • Custom Pages199
  • Installing the User Database199
  • Summary201
  • Chapter 7: Content Security and OPSEC203
  • Introduction204
  • OPSEC204
  • Part nership205
  • Anti-virus205
  • Web Filtering205
  • OPSEC Applications205
  • Security Servers206
  • URI207
  • SMTP210
  • FTP214
  • TCP216
  • CIFS217
  • CVP218
  • Resource Creation218
  • UFP219
  • Resource Creation220
  • MDQ221
  • How to Debug221
  • Secure Internal Communication221
  • Summary222
  • Chapter 8: VPN223
  • Introduction224
  • Encryption Overview224
  • Symmetric and Asymmetric Encryption224
  • Certificate Authorities225
  • Exchanging Keys225
  • Tunnel Mode vs. Transport Mode226
  • Encryption Algorithms226
  • Hashing Algorithms226
  • Public Key Infrastructure227
  • Simplified vs. Traditional227
  • Using the Simplified Configuration Method228
  • VPN Communities229
  • Meshed VPN Communities229
  • Star VPN Communities233
  • Multiple Entry Point (MEP)236
  • Installing the Policy238
  • Configuring a VPN with a Cisco PIX240
  • Using the Traditional VPN Configuration Method241
  • VPN Directional Matching243
  • Route-Based VPN244
  • Routing Protocols244
  • Configuring VTIs245
  • Configuring VTI Example245
  • Tunnel Management and Debugging246
  • Using SmartView Tracker247
  • Using cpstat248
  • Summary251
  • Chapter 9: SecuRemote, SecureClient, and Integrity253
  • Introduction254
  • SecuRemote254
  • What's New with SecuRemote in NGX?254
  • Standard Client255
  • Basic Remote Access255
  • Defining the Connection Policy256
  • SecuRemote Installation and Configuration on Microsoft Windows274
  • Connecting to the VPN-1 Gateway285
  • SecureClient287
  • What's New in SC NGX?287
  • Installing SecureClient on Microsoft Windows288
  • Policy Server288
  • Desktop Security Policies288
  • Configuring Desktop Security Policies289
  • Disabling the Security Policy294
  • Secure Configuration Verification295
  • Office Mode295
  • Why Office Mode?296
  • Client IP Pool296
  • Configuring Office Mode with IP Pools296
  • Configuring the VPN-1 Gateway for Office Mode297
  • Configuring SecureClient for Office Mode300
  • Secure Configuration Verification (SCV)301
  • What's New with Secure Configuration Verification (SCV) in NGX?302
  • Configuring the Policy Server to Enable Secure Configuration Verification (SCV)303
  • Secure Configuration Verification (SCV) Checks Available304
  • Check Point OPSEC Vendor SCV Checks304
  • Other Third-Party Checks304
  • Create Your Own Checks304
  • Integrity304
  • History of Integrity305
  • Integrity Client Installation306
  • Integrity Client Configuration309
  • Integrity Clientless Security309
  • Summary310
  • Chapter 10: Adaptive Security Device Manager311
  • Introduction312
  • Features, Limitations, and Requirements312
  • Supported PIX Firewall Hardware and Software Versions313
  • PIX Device Requirements313
  • Host Requirements for Running ASDM313
  • Adaptive Security Device Manager Limitations313
  • Unsupported Commands314
  • Unsupported Characters314
  • ASDM CLI Does Not Support Interactive Commands314
  • Printing from ASDM315
  • Installing, Configuring, and Launching ASDM315
  • Preparing for Installation315
  • Installing or Upgrading ASDM315
  • Obtaining a DES Activation Key316
  • Configuring the PIX Firewall for Network Connectivity316
  • Installing a TFTP Server317
  • Upgrading the PIX Firewall and Configuring the DES Activation Key317
  • Installing or Upgrading ASDM on the PIX Device317
  • Enabling and Disabling ASDM318
  • Launching ASDM318
  • Configuring the PIX Firewall Using ASDM332
  • Using the Startup Wizard333
  • Configuring System Properties340
  • The AAA Menu343
  • The Advanced Menu345
  • The ARP Static Table Menu349
  • The Auto Update Menu350
  • The DHCP Services Menu352
  • The DNS Client Menu354
  • The Failover Menu354
  • The History Metrics Category358
  • The IP Audit Menu359
  • The Logging Menu361
  • The Priority Queue Category367
  • The SSL Category368
  • The SunRPC Server Category369
  • The URL Filtering Category370
  • Configuring VPNs Using ASDM371
  • Configuring a Site-to-Site VPN Using ASDM371
  • Configuring a Remote Access VPN Using ASDM378
  • Summary386
  • Chapter 11: Application Inspection387
  • New Features in PIX 7.0388
  • Supporting and Securing Protocols389
  • TCP, UDP, ICMP, and the PIX Firewall390
  • Application Layer Protocol Inspection392
  • Defining a Traffic Class392
  • Associating a Traffic Class with an Action395
  • Customizing Application Inspection Parameters397
  • Applying Inspection to an Interface397
  • Domain Name Service397
  • Remote Procedure Call398
  • SQL*Net399
  • Internet Locator Service and Lightweight Directory Access Protocol400
  • HTTP Inspection401
  • FTP Inspection402
  • Active versus Passive Mode402
  • ESMTP Inspection405
  • ICMP Inspection406
  • H.323406
  • Simple Network Management Protocol (SNMP)407
  • Voice and Video Protocols408
  • SIP408
  • CTIQBE408
  • SCCP409
  • Real-Time Streaming Protocol (RTSP), NetShow, and VDO Live409
  • Summary411
  • Chapter 12: Filtering, Intrusion Detection, and Attack Management413
  • New Features in PIX 7.0414
  • Enhanced TCP Security Engine414
  • Improved Websense URL Filtering Performance414
  • Introduction414
  • Filtering Web and FTP Traffic414
  • Filtering URLs415
  • Websense and Sentian by N2H2415
  • Fine-Tuning and Monitoring the Filtering Process416
  • Configuring HTTP URL Filtering419
  • Configuring HTTPS Filtering420
  • Setting Up FTP Filtering420
  • Active Code Filtering421
  • Filtering Java Applets422
  • Filtering ActiveX Objects422
  • Virus Filtering; Spam, Adware, Malware, and Other-Ware Filtering423
  • TCP Attack Detection and Response424
  • PIX Intrusion Detection425
  • Supported Signatures425
  • Configuring Intrusion Detection/Auditing428
  • Disabling Signatures430
  • Configuring Shunning430
  • Attack Containment and Management431
  • Placing Limits on Fragmentation431
  • SYN FloodGuard432
  • The TCP Intercept Feature432
  • Preventing IP Spoofing432
  • Other Ways the PIX Can Prevent, Contain, or Manage Attacks433
  • Configuring Connection Limits and Timeouts433
  • Preventing MAC Address Spoofing435
  • Summary437
  • Chapter 13: Services439
  • Introduction440
  • DHCP Functionality440
  • DHCP Servers440
  • Cisco IP Phone-Related Options442
  • DHCP Relay443
  • DHCP Clients443
  • PPPoE444
  • EasyVPN446
  • EasyVPN Server446
  • Routing and the PIX Firewall447
  • Unicast Routing448
  • Static Routes448
  • RIP449
  • OSPF450
  • Network Address Translation as a Routing Mechanism451
  • Multicast Routing451
  • Stub Multicast Routing452
  • PIM Multicast Routing452
  • BGP through PIX Firewall453
  • Queuing and Policing453
  • Summary455
  • Chapter 14: Configuring Authentication, Authorization, and Accounting457
  • Introduction458
  • New and Changed Commands in 7.0458
  • Introducing AAA Concepts459
  • Authentication461
  • Authorization462
  • Accounting463
  • AAA Security Protocols463
  • RADIUS463
  • Authentication Methods Used by RADIUS464
  • RADIUS Functions Available on the Cisco PIX464
  • How RADIUS Works464
  • TACACS+466
  • Authentication Methods Used by TACACS+466
  • TACACS+ Functions Available to the Cisco PIX466
  • How TACACS+ Works467
  • Optional Security Protocols and Methods468
  • AAA Servers469
  • Configuring Console Authentication469
  • Configuring Local Authentication470
  • Configuring Local AAA Using the ASDM472
  • Configuring Command Authorization474
  • Configuring Local Command Authorization475
  • Configuring TACACS+ and RADIUS Console Authentication476
  • Configuring TACACS+ Command Authorization480
  • Configuring Authentication for Traffic through the Firewall483
  • Configuring Cut-through Proxy483
  • Virtual HTTP484
  • Virtual Telnet486
  • Configuring Authorization for Traffic through the Firewall487
  • Configuring Accounting for Traffic through the Firewall488
  • Summary490
  • Chapter 15: PIX Firewall Management491
  • Introduction492
  • Configuring Logging492
  • Logging Levels493
  • Dropped and Changed Syslog Messages from 6.x494
  • Logging Facility501
  • Local Logging502
  • Buffered Logging503
  • Console Logging503
  • Terminal Logging504
  • Remote Logging via Syslog504
  • Disabling Specific Syslog Messages509
  • Configuring Remote Access510
  • Secure Shell510
  • Enabling SSH Access511
  • Troubleshooting SSH516
  • Telnet519
  • Restrictions520
  • Configuring Simple Network Management Protocol520
  • Configuring System Identification521
  • Configuring Polling521
  • Configuring Traps524
  • Managing SNMP on the PIX524
  • Configuring System Date and Time526
  • Setting and Verifying the Clock and Time Zone526
  • Configuring and Verifying the Network Time Protocol529
  • NTP Authentication530
  • Management Using the Cisco PIX Adaptive Security Device Manager (ASDM)532
  • Summary537
  • Chapter 16: Configuring Virtual Private Networking539
  • Introduction540
  • What's New in PIX 7.0541
  • IPsec Concepts541
  • IPsec541
  • IPsec Core Layer 3 Protocols: ESP and AH542
  • Authentication Header542
  • Encapsulating Security Payload543
  • IPsec Communication Modes: Tunnel and Transport543
  • Internet Key Exchange545
  • Security Associations547
  • Certificate Authority Support550
  • Configuring a Site-to-Site VPN550
  • Planning551
  • Allowing IPsec Traffic552
  • Enabling IKE552
  • Creating an ISAKMP Protection Suite553
  • Defining an ISAKMP Preshared Key554
  • Configuring Certificate Authority Support554
  • Preparing the PIX to Use Certificates556
  • Generating a Key Pair557
  • Configure a CA as a Trustpoint558
  • Authenticating and Enrolling with the CA559
  • Configuring Crypto Access-Lists560
  • Defining a Transform Set561
  • Bypassing Network Address Translation562
  • Configuring a Crypto Map562
  • Troubleshooting564
  • Remote Access-Configuring Support for the Cisco Software VPN Client565
  • Enabling IKE and Creating an ISAKMP Protection Suite567
  • Defining a Transform Set567
  • Crypto Maps567
  • Tunnel Groups and Group Policies568
  • Address Pool Configuration568
  • Split Tunneling569
  • NAT Issues570
  • Authentication against Radius, TACACS+, SecurID, or Active Directory570
  • Automatic Client Update571
  • Configuring Client Firewall Requirements571
  • Sample Configurations of PIX and VPN Clients571
  • Summary577
  • Chapter 17: ISA Server 2006 Client Types and Automating Client Provisioning579
  • Introduction580
  • Understanding ISA Server 2006 Client Types580
  • Understanding the ISA Server 2006 SecureNAT Client582
  • SecureNAT Client Limitations584
  • SecureNAT Client Advantages587
  • Name Resolution for SecureNAT Clients589
  • Name Resolution and "Looping Back" Through the ISA Server 2006 Firewall589
  • Understanding the ISA Server 2006 Firewall Client593
  • Allows Strong User/Group-Based Authentication for All Winsock Applications Using TCP and UDP Protoco594
  • Allows User and Application Information to be Recorded in the ISA Server 2006 Firewall's Log Files594
  • Provides Enhanced Support for Network Applications, Including Complex Protocols That Require Seconda595
  • Provides "Proxy" DNS Support for Firewall Client Machines595
  • The Network Routing Infrastructure Is Transparent to the Firewall Client596
  • How the Firewall Client Works598
  • Installing the Firewall Client Share599
  • Installing the Firewall Client600
  • Firewall Client Configuration601
  • Centralized Configuration Options at the ISA Server 2006 Firewall Computer601
  • Enabling Support for Legacy Firewall Client/Winsock Proxy Clients604
  • Client Side Firewall Client Settings605
  • Firewall Client Configuration Files607
  • .ini Files608
  • Advanced Firewall Client Settings609
  • Firewall Client Configuration at the ISA Server 2006 Firewall611
  • ISA Server 2006 Web Proxy Client613
  • Improved Performance for the Firewall Client and SecureNAT Client Configuration for Web Access613
  • Ability to Use the Autoconfiguration Script to Bypass Sites Using Direct Access614
  • Allows You to Provide Web Access (HTTP/HTTPS/FTP Download) without Enabling Users Access to Other Pr614
  • Allows You to Enforce User/Group-based Access Controls Over Web Access615
  • Allows you to Limit the Number of Outbound Web Proxy Client Connections621
  • Supports Web Proxy Chaining, Which Can Further Speed Up Internet Access623
  • ISA Server 2006 Multiple Client Type Configuration623
  • Deciding on an ISA Server 2006 Client Type624
  • Automating ISA Server 2006 Client Provisioning626
  • Configuring DHCP Servers to Support Web Proxy and Firewall Client Autodiscovery627
  • Install the DHCP Server628
  • Create the DHCP scope628
  • Create the DHCP 252 Scope Option and Add It to the Scope631
  • Configure the Client as a DHCP Client634
  • Configure the Client Browser to Use DCHP for Autodiscovery635
  • Configure the ISA Server 2006 Firewall to Publish Autodiscovery Information635
  • Making the Connection636
  • Configuring DNS Servers to Support Web Proxy and Firewall Client Autodiscovery638
  • Creating the wpad Entry in DNS638
  • Configure the Client to Use the Fully-Qualified wpad Alias641
  • Configure the client browser to use autodiscovery644
  • Configure the ISA Server 2006 Firewall to Publish Autodiscovery Information645
  • Making the Connection Using DNS for Autodiscovery645
  • Automating Installation of the Firewall Client646
  • Configuring Firewall Client and Web Proxy Client Configuration in the ISA Management Console647
  • Group Policy Software Installation651
  • Silent Installation Script654
  • Systems Management Server (SMS)654
  • Summary655
  • Chapter 18: Installing and Configuring the ISA Firewall Software657
  • Pre-installation Tasks and Considerations658
  • System Requirements658
  • Configuring the Routing Table660
  • DNS Server Placement661
  • Configuring the ISA Firewall's Network Interfaces663
  • Installation via a Terminal Services Administration Mode Session668
  • Performing a Clean Installation on a Multihomed Machine668
  • Default Post-installation ISA Firewall Configuration674
  • The Post-installation System Policy676
  • Performing a Single NIC Installation (Unihomed ISA Firewall)686
  • Quick Start Configuration for ISA Firewalls688
  • Configuring the ISA Firewall's Network Interfaces690
  • IP Address and DNS Server Assignment690
  • Configuring the Internal Network Interface690
  • Configuring the External Network Interface691
  • Network Interface Order691
  • Installing and Configuring a DNS Server on the ISA Server Firewall692
  • Installing the DNS Service692
  • Installing the DNS Server Service on Windows Server 2003693
  • Configuring the DNS Service on the ISA Firewall693
  • Configuring the DNS Service in Windows Server 2003693
  • Configuring the DNS Service on the Internal Network DNS Server696
  • Installing and Configuring a DHCP Server on the ISA Server Firewall698
  • Installing the DHCP Service698
  • Installing the DHCP Server Service on a Windows Server 2003 Computer698
  • Configuring the DHCP Service699
  • Installing and Configuring the ISA Server 2006 Software700
  • Configuring the ISA Firewall703
  • DHCP Request to Server Rule705
  • DHCP Reply from Server Rule707
  • Internal DNS Server to DNS Forwarder Rule708
  • Internal Network to DNS Server710
  • The All Open Rule710
  • Configuring the Internal Network Computers711
  • Configuring Internal Clients as DHCP Clients712
  • Hardening the Base ISA Firewall Configuration and Operating System714
  • ISA Firewall Service Dependencies715
  • Service Requirements for Common Tasks Performed on the ISA Firewall717
  • Client Roles for the ISA Firewall720
  • ISA Firewall Administrative Roles and Permissions722
  • Lockdown Mode724
  • Lockdown Mode Functionality724
  • Connection Limits725
  • DHCP Spoof Attack Prevention727
  • Summary731
  • Chapter 19: Creating and Using ISA 2006 Firewall Access Policy733
  • ISA Firewall Access Rule Elements736
  • Protocols736
  • User Sets737
  • Content Types737
  • Schedules739
  • Network Objects739
  • Configuring Access Rules for Outbound Access through the ISA Firewall739
  • The Rule Action Page740
  • The Protocols Page740
  • The Access Rule Sources Page743
  • The Access Rule Destinations Page743
  • The User Sets Page744
  • Access Rule Properties745
  • The General Tab745
  • The Action Tab745
  • The Protocols Tab746
  • The From Tab748
  • The To Tab749
  • The Users Tab750
  • The Schedule Tab751
  • The Content Types Tab752
  • The Access Rule Context Menu Options753
  • Configuring RPC Policy754
  • Configuring FTP Policy755
  • Configuring HTTP Policy756
  • Ordering and Organizing Access Rules756
  • How to Block Logging for Selected Protocols757
  • Disabling Automatic Web Proxy Connections for SecureNAT Clients758
  • Using Scripts to Populate Domain Name Sets759
  • Using the Import Scripts762
  • Extending the SSL Tunnel Port Range for Web Access to Alternate SSL Ports767
  • Avoiding Looping Back through the ISAFirewall for Internal Resources770
  • Anonymous Requests Appear in Log File Even When Authentication is Enforced For Web (HTTP Connections770
  • Blocking MSN Messenger using an Access Rule771
  • Allowing Outbound Access to MSN Messenger via Web Proxy774
  • Changes to ISA Firewall Policy Only Affects New Connections775
  • Allowing Intradomain Communications through the ISA Firewall776
  • Summary785
  • Chapter 20: Creating Remote Access and Site-to-Site VPNs with ISA Firewalls787
  • Overview of ISA Firewall VPN Networking788
  • Firewall Policy Applied to VPN Client Connections789
  • Firewall Policy Applied to VPN Site-to-Site Connections791
  • VPN Quarantine791
  • User Mapping of VPN Clients793
  • SecureNAT Client Support for VPN Connections794
  • Site-to-Site VPN Using Tunnel Mode IPSec795
  • Publishing PPTP VPN Servers795
  • Pre-shared Key Support for IPSec VPN Connections795
  • Advanced Name Server Assignment for VPN Clients796
  • Monitoring of VPN Client Connections797
  • An Improved Site-to-Site Wizard (New ISA 2006 feature)797
  • The Create Answer File Wizard (New ISA 2006 feature)798
  • The Branch Office Connectivity Wizard (New ISA 2006 feature)798
  • The Site-to-Site Summary (New ISA 2006 feature)799
  • Creating a Remote Access PPTP VPN Server799
  • Enable the VPN Server799
  • Create an Access Rule Allowing VPN Clients Access to Allowed Resources811
  • Enable Dial-in Access813
  • Test the PPTP VPN Connection816
  • Creating a Remote Access L2TP/IPSec Server818
  • Issue Certificates to the ISA Firewall and VPN Clients818
  • Test the L2TP/IPSec VPN Connection822
  • Monitor VPN Clients823
  • Using a Pre-shared Key for VPN Client Remote Access Connections825
  • Creating a PPTP Site-to-Site VPN827
  • Create the Remote Site Network at the Main Office829
  • The Network Rule at the Main Office837
  • The Access Rules at the Main Office838
  • Create the VPN Gateway Dial-in Account at the Main Office839
  • Create the Remote Site Network at the Branch Office840
  • The Network Rule at the Branch Office842
  • The Access Rules at the Branch Office843
  • Create the VPN Gateway Dial-in Account at the Branch Office843
  • Activate the Site-to-Site Links844
  • Creating an L2TP/IPSec Site-to-Site VPN845
  • Enable the System Policy Rule on the Main Office Firewall to Access the Enterprise CA846
  • Request and Install a Certificate for the Main Office Firewall848
  • Configure the Main Office ISA Firewall to use L2TP/IPSec for the Site-to-Site Link851
  • Enable the System Policy Rule on the Branch Office Firewall to Access the Enterprise CA855
  • Request and Install a Certificate for the Branch Office Firewall856
  • Configure the Branch Office ISA Firewall to use L2TP/IPSec for the Site-to-Site Link857
  • Activate the L2TP/IPSec Site-to-Site VPN Connection858
  • Configuring Pre-shared Keys for Site-to-Site L2TP/IPSec VPN Links859
  • IPSec Tunnel Mode Site-to-Site VPNs with Downlevel VPN Gateways859
  • Using RADIUS for VPN Authentication and Remote Access Policy860
  • Configure the Internet Authentication Services (RADIUS) Server861
  • Create a VPN Clients Remote Access Policy862
  • Remote Access Permissions and Domain Functional Level865
  • Changing the User Account Dial-in Permissions866
  • Changing the Domain Functional Level867
  • Controlling Remote Access Permission via Remote Access Policy869
  • Enable the VPN Server on the ISA Firewall and Configure RADIUS Support870
  • Create an Access Rule Allowing VPN Clients Access to Approved Resources873
  • Make the Connection from a PPTP VPN Client875
  • Using EAP User Certificate Authentication for Remote Access VPNs877
  • Configuring the ISA Firewall Software to Support EAP Authentication878
  • Enabling User Mapping for EAP Authenticated Users879
  • Issuing a User Certificate to the Remote Access VPN Client Machine880
  • Supporting Outbound VPN Connections through the ISA Firewall884
  • Installing and Configuring the DHCP Server and DHCP Relay Agent on the ISA Firewall886
  • Summary889
  • Chapter 21: ISA 2006 Stateful Inspection and Application Layer Filtering891
  • Introduction892
  • Application Filters892
  • The SMTP Filter893
  • The DNS Filter894
  • The POP Intrusion Detection Filter895
  • The SOCKS V4 Filter895
  • The FTP Access Filter897
  • The H.323 Filter897
  • The MMS Filter897
  • The PNM Filter898
  • The PPTP Filter898
  • The RPC Filter898
  • The RTSP Filter898
  • Web Filters899
  • The HTTP Security Filter (HTTP Filter)899
  • Overview of HTTP Security Filter Settings900
  • The General Tab900
  • The Methods Tab902
  • The Extensions Tab904
  • The Headers Tab905
  • The Signatures Tab909
  • HTTP Security Filter Logging912
  • Exporting and Importing HTTP Security Filter Settings913
  • Exporting an HTTP Policy from a Web Publishing Rule913
  • Importing an HTTP Policy into a Web Publishing Rule914
  • Investigating HTTP Headers for Potentially Dangerous Applications915
  • Example HTTP Security Filter Policies919
  • Commonly Blocked Headers and Application Signatures923
  • The ISA Server Link Translator924
  • Determining Custom Dictionary Entries927
  • Configuring Custom Link Translation Dictionary Entries927
  • The Web Proxy Filter929
  • The OWA Forms-Based Authentication Filter930
  • The RADIUS Authentication Filter931
  • IP Filtering and Intrusion Detection/Intrusion Prevention931
  • Common Attacks Detection and Prevention932
  • DNS Attacks Detection and Prevention933
  • IP Options and IP Fragment Filtering934
  • Source Routing Attack935
  • Summary937
  • Chapter 22: Deploying NetScreen Firewalls939
  • Introduction940
  • Managing the NetScreen Firewall940
  • NetScreen Management Options941
  • Serial Console941
  • Telnet941
  • Secure Shell942
  • WebUI942
  • The NetScreen-Security Manager943
  • Administrative Users943
  • The Local File System and the Configuration File944
  • Using the Command Line Interface948
  • Using the Web User Interface951
  • Securing the Management Interface951
  • Updating ScreenOS966
  • System Recovery967
  • Configuring NetScreen970
  • Types of Zones970
  • Security Zones970
  • Tunnel Zones971
  • Function Zones971
  • Virtual Routers971
  • Types of Interfaces971
  • Security Zone Interfaces971
  • Physical Interfaces971
  • Subinterfaces972
  • Aggregate Interfaces972
  • Redundant Interfaces972
  • VLAN1 Interface973
  • Virtual Security Interfaces973
  • Function Zone Interfaces973
  • Management Interfaces973
  • HA Interfaces973
  • Tunnel Interfaces973
  • Loopback Interfaces974
  • Configuring Security Zones974
  • Configuring Your NetScreen for the Network979
  • Binding an Interface to a Zone979
  • Setting up IP Addressing980
  • Configuring the DHCP Client980
  • Using PPPoE981
  • Interface Speed Modes983
  • Port Mode Configuration983
  • Configuring Basic Network Routing984
  • Configuring System Services987
  • Setting The Time987
  • DHCP Server989
  • DNS993
  • SNMP994
  • Syslog997
  • WebTrends998
  • Resources999
  • Summary1000
  • Chapter 23: Policy Configuration1001
  • Introduction1002
  • NetScreen Policies1002
  • Theory Of Access Control1004
  • Types of NetScreen Policies1005
  • Intrazone Policies1006
  • Interzone Policies1007
  • Global Policies1007
  • Default Policy1007
  • Policy Checking1007
  • Getting Ready to Make a Policy1009
  • Policy Components1010
  • Zones1010
  • Address Book Entries1010
  • Creating Address Book Entries1010
  • Modifying and Deleting Address Book Entries1013
  • Address Groups1013
  • Services1015
  • Creating Custom Services1015
  • Modifying and Deleting Services1017
  • Service Groups1017
  • Creating Policies1019
  • Creating a Policy1019
  • Creating a Policy via the WebUI1019
  • Reordering Policies in the WebUI1022
  • Other Policy Options in the WebUI1023
  • Creating a Policy via the CLI1024
  • Other Policy Options Available in the CLI1027
  • Summary1029
  • Chapter 24: User Authentication1031
  • Introduction1032
  • Types of Users1032
  • Uses of Each Type1032
  • Auth Users1032
  • IKE Users1033
  • L2TP Users1034
  • XAuth Users1034
  • Admin Users1034
  • User Databases1034
  • Local Database1034
  • Types of Users1035
  • Features1035
  • External Auth Servers1035
  • Object Properties1035
  • Auth Server Types1036
  • RADIUS1036
  • Types of Users1036
  • Features1037
  • How to Configure1037
  • SecurID1038
  • Types of Users1038
  • Features1038
  • How to Configure1038
  • LDAP1039
  • Types of Users1040
  • Features1040
  • How to Configure1040
  • Default Auth Servers1041
  • How to Change1041
  • When to Use1042
  • Authentication Types1042
  • Auth Users and User Groups1042
  • IKE Users and User Groups1043
  • XAuth Users and User Groups1044
  • L2TP Users and User Groups1046
  • Admin Users and User Groups1047
  • Multi-type Users1049
  • User Groups and Group expressions1049
  • Chapter 25: Routing1051
  • Introduction1052
  • Virtual Routers1052
  • Using Virtual Routers1052
  • Creating Virtual Routers1053
  • Route Selection1054
  • Set Route Preference1055
  • Set Route Metric1056
  • Route Redistribution1058
  • Configuring a Route Access List1059
  • Configuring A Route Map1060
  • Routing Information Protocol1061
  • RIP Concepts1061
  • Basic RIP Configuration1061
  • Configuring RIP1062
  • Open Shortest Path First (OSPF)1065
  • OSPF Concepts1065
  • Basic OSPF Configuration1066
  • Border Gateway Protocol1070
  • Basic BGP Configuration1070
  • Summary1074
  • Chapter 26: Address Translation1075
  • Introduction1076
  • Purpose of Address Translation1076
  • Advantages of Address Translation1076
  • Disadvantages of Address Translation1078
  • NetScreen NAT Overview1078
  • NetScreen Packet Flow1079
  • Source NAT1081
  • Interface-based Source Translation1081
  • MIP1082
  • MIP Limitations1082
  • MIP Scenarios1083
  • Scenario 11084
  • Scenario 21084
  • Scenario 31086
  • Policy-based Source NAT1087
  • DIP1088
  • Sticky DIP1090
  • DIP Shift1091
  • Destination NAT1093
  • VIP1093
  • Policy-based Destination NAT1094
  • Destination NAT Scenarios1094
  • One-to-One Mapping1095
  • Many-to-one Mapping1095
  • Many-to-Many Mapping1097
  • Destination PAT Scenario1099
  • Source and Destination NAT Combined1100
  • Summary1101
  • Index1103
Book details
  • Vendor Elsevier S & T
  • SKU 9781597492188
  • ISBN-13 9780080556871
  • Author Shinder, Thomas W
  • Edition 2nd
  • Category Computers
  • Subject General

Do you have questions about this book?

Ask an expert!

The Second Edition of the Best Damn Firewall Book Period is completely revised and updated to include all of the most recent releases from Microsoft, Cisco, Juniper Network, and Check Point.

Compiled from the best of the Syngress firewall library and authored by product experts such as Dr. Tom Shinder on ISA Server, this volume is an indispensable addition to a serious networking professionals toolkit.

Coverage includes migrating to ISA Server 2006, integrating Windows Firewall and Vista security into your enterprise, successfully integrating Voice over IP applications around firewalls, and analyzing security log files.

Sections are organized by major vendor, and include hardware, software and VPN configurations for each product line.

New to this Edition:

* Microsoft firewall protection, from Windows Firewall to ISA Server 2006
* Cisco PIX Version 7, including VPN configuration and IDS
* Analyzing Firewall Logs and Reports
* VoIP and Firewall Bypassing