Gauntlet Security; What And How Gauntlet Protects; Gauntlet And The Firewall - RuggedCom RuggedRouter RX1000 User Manual

Ruggedcom router user manual
Hide thumbs Also See for RuggedRouter RX1000:
Table of Contents

Advertisement

RuggedRouter
User Guide

Gauntlet Security

RX1100 owners can use the Gauntlet security appliance to restrict access to critical
assets. This section details how to activate Gauntlet and determine currently
negotiated sessions. Details and recommendations on applying the Gauntlet system
to networking may be found in texts referenced in the About This Guide section of
the user guide.

What And How Gauntlet Protects

Gauntlet protects against unauthorized access to critical assets, including the router
itself. Gauntlet allows connection from known management devices to assets behind
the firewall operating on known TCP/UDP port numbers. Gauntlet does not encrypt
communications which occur in the clear, such as the Telnet protocol. Protocols such
as SSH and HTTPS offer their own encryption and are suitable for use with Gauntlet.

Gauntlet And The Firewall

Gauntlet integrates tightly with the firewall, opening it for communications between
vetted clients and critical assets on a demand basis. There are three steps in
activating the Gauntlet security appliance.
1. The firewall must be configured with some default rules required by the
appliance (described below), and then activated or restarted.
2. The rrsetup utility must be used to configure a Gauntlet passphrase and enable
the Gauntlet daemon.
3. The Gauntlet daemon and Shorewall must both be enabled in the Webmin
Bootup and Shutdown Menu to "Start at boot".
Shorewall requires you to assign the router interfaces to zones and then control traffic
between these zones.
Typically, the zone for WAN interfaces is named "net" while the zone for local
interfaces is named "loc". The following instructions assume those names.
The gauntlet daemon requires rules for certain ports (shown below) to be installed.
Contact RuggedCom support for assistance if you wish to reassign these ports.
1. Visit the Shorewall Network Zones sub-menu and create the net and loc IPv4
zones.
2. Visit the Network Interfaces sub-menu and assign interfaces to the zones.
3. Visit the Default Policies sub-menu and assign the following policies:
Source zone
fw
loc
all
4. Visit the Firewall Rules sub-menu and assign the following rules:
Action
ACCEPT
ACCEPT
Gauntlet
Gauntlet
Gauntlet
240
Destination zone
Policy
any
ACCEPT
net
ACCEPT
any
REJECT
Source zone Destination zone Protocol
net
fw
net
fw
net
loc
net
fw
net
fw
Src-Port
Dst-Port
UDP
any
30000
UDP
any
30001
TCP
any
31000
TCP
any
31002
RuggedCom

Hide quick links:

Advertisement

Table of Contents
loading

This manual is also suitable for:

Ruggedrouter rx1100

Table of Contents