Cyclades-PR4000

Exterior Router

The exterior router is the network’s first defense against attacks. For this reason, it is reasonable to prohibit all packets except for those explicitly allowed. This is done by choosing the Default Scope to be Deny. Thus, ALL desired traffic must be expressly allowed by the rules in the rule list.

DENY

Let

e-mail out

Wo

 

 

 

rl

 

 

 

d

 

 

 

of

 

 

 

P

 

 

 

o

 

 

 

s

 

 

 

s

 

 

 

i

 

 

 

b

 

 

 

l

 

 

 

e

 

 

 

P

 

 

 

a

 

 

 

c

 

Let

 

k

 

 

s

 

 

 

e

 

 

 

t

 

e-mail in

 

 

DENY

 

DENY

Let Telnet

Connections Out

FIGURE 12.3 DENY AS DEFAULT SCOPE

In Figure 12.3, a conceptual equivalent of the interface is shown. All packets except those which fall into the holes in the ball will be denied entry in to or out of the network.

Chapter 14 - Filters and Rules

126

Page 126
Image 126
Avocent Cyclades-PR4000 installation manual Exterior Router, Let Mail out, Let Telnet Connections Out