Juniper防火墙基本安全策略.ppt
《Juniper防火墙基本安全策略.ppt》由会员分享,可在线阅读,更多相关《Juniper防火墙基本安全策略.ppt(41页珍藏版)》请在三一办公上搜索。
1、Juniper防火墙安全策略ITman论坛,Security Zones and Policies,Inter-Zone traffic must be checked by policyIntra-Zone traffic may be checked by policy,ExternalZone,PrivateZone,B,PublicZone,.254,A,B,C,D,.1.254,.1.254,.254.1,Src IP Dest IP Protocol Src Port Dst Port Data 10.1.10.5 1.1.70.250 06 36033 80#$%&,Policy
2、 Components,Source&DestinationAddress BookAddress GroupServicePre-defined ServiceCustom ServiceCustom Service Group,ActionPermitDenyTunnelOptionsCovered in next chapter,Policy Configuration Procedure,Create Address Book entries for each zoneDefine any custom services needed for your networkCreate po
3、licy entriesSort policy set for proper ordering,Step 1:Address Book Entries,ExternalZone,PrivateZone,B,PublicZone,.254,A,B,C,D,.1.254,.1.254,.254.1,Address Book-WebUI,Entries displayed based on zoneUse alphabet buttons to filter display when large numbers of addresses are configuredClick on“New”butt
4、on to add an entry,Objects Addresses List,New Address Entry,Address name is used in address list and policy listMake the name meaningful to your network!Comment is your opportunity for embedded documentationChoice of address/mask or domain nameDomain name requires DNS configuration,Objects Addresses
5、 List(New),Address Book CLI,set address/,set address ns208-set Yahoo,ns208-get addressaddr zone name PrivatePrivate Addresses:Name Address Netmask Flag CommentsAny 0.0.0.0 0.0.0.0 02 All AddrDial-Up VPN 255.255.255.255 255.255.255.255 02 Dial-Up VPN AddrPrivatePC 10.1.10.5 255.255.255.255 00,IP Addr
6、ess,Viewing the address book,Domain name,Step 2:Services,Address book entries define where traffic can flow from and toService entries define the type of trafficProtocol and port numbers,Predefined Services,get service pre-defined,Objects Services Predefined,Creating a Custom Service,set service nam
7、e,Objects Services Custom(New),Step 3:Create Policy-WebUI,Select zone pairs,then click“New”,Policies,Create Policy-WebUI,Components Source&Destination ZoneSource&Destination AddressUse pull-down menu to display address book entriesServiceUse pull-down menu to display service entriesActionPermit,deny
8、,or tunnel,Create Policy CLI,set policy from to permit|denyExample:,Viewing Policy Entries WebUI,Policies,Viewing Policy Entries-CLI,ns208-get policyTotal regular policies 6,Default deny.ID From To Src-address Dst-address Service Action State ASTLCB 1 Private Public Any Any H.323 Deny enabled-X 2 Pr
9、ivate Public Admins 1.1.70.250/Allowed Permit enabled-X 3 Private Public 10.1.10.100 1.1.70.200/ANY Permit enabled-X 4 Private Public 10.1.10.16/1.1.70.200/Allowed Permit enabled-X 5 Private Public Any 1.1.70.200/HTTP Deny enabled-X 6 Private Public Any 1.1.70.200/FTP Permit enabled-X,Step 4:Policy
10、Ordering,New policies added to end of listDefault condition is deny all trafficOrder is important!,Re-Ordering Policies-WebUI,Button allows move by numberArrow allows placement by position(point and click),Move Button,Move Arrow,Re-Ordering Policies(cont.),Using the buttonUsing the Arrows,Re-Orderin
- 配套讲稿:
如PPT文件的首页显示word图标,表示该PPT已包含配套word讲稿。双击word图标可打开word文档。
- 特殊限制:
部分文档作品中含有的国旗、国徽等图片,仅作为作品整体效果示例展示,禁止商用。设计者仅对作品中独创性部分享有著作权。
- 关 键 词:
- Juniper 防火墙 基本 安全策略
链接地址:https://www.31ppt.com/p-5436435.html