Filter-Based Security; Figure 7-7: Security Topology Example - Nortel Web OS Switch Software Application Manual

Switch software
Table of Contents

Advertisement

Filter-based Security

This section provides an example of configuring filters for providing the best security. It is
generally recommended that you configure filters to deny all traffic except for those services
that you specifically wish to allow. Consider the following sample network:
Local Clients
Figure 7-7 Security Topology Example
In this example, the network is made of local clients on a collector switch, a Web server, a mail
server, a domain name server, and a connection to the Internet. All the local devices are on the
same subnet.
For best security, it is generally recommended that you configure filters to deny all traffic
except for those services that you specifically wish to allow. In this example, the administrator
wishes to install basic security filters to allow only the following traffic:
n
External HTTP access to the local Web server
n
External SMTP (mail) access to the local mail server
n
Local clients browsing the World Wide Web
n
Local clients using Telnet to access sites outside the intranet
n
DNS traffic
All other traffic is denied and logged by the default filter.
N
OTE
ing does not replace the necessity for a well-constructed network firewall.
212777-A, February 2002
Client Switch
Web Server
205.177.15.2
Since IP address and port information can be manipulated by external sources, filter-
Alteon Web Switch
Router
Mail Server
DNS
205.177.15.3
205.177.15.4
Web OS 10.0 Application Guide
Internet
Chapter 7: Filtering
n
185

Advertisement

Table of Contents
loading

This manual is also suitable for:

Web os 10.0

Table of Contents