Ethical Hacking Learn to find vulnerabilities before the bad guys do! Gain real world hands on hacking experience in our state of the art hacking lab. Course designed and taught by expert instructors with years of penetration testing experience. 12 student maximum in every class. Certification attempt included in every package. | Computer Forensics Training at InfoSec Institute Gain the in-demand skills of a certified computer examiner, learn to recover trace data left behind by fraud, theft, and cybercrime perpetrators. Discover the source of computer crime and abuse at your organization so that it never happens again. All of our class sizes are guaranteed to be 12 students or less to facilitate one-on-one interaction with one of our expert instructors. |

| Subject: | Re: Firewall rules standards |
|---|---|
| Date: | Wed, 30 Mar 2005 13:39:07 -0700 |
On Wed, 2005-03-30 at 14:11 +1000, Tran, Nhon wrote:
I support a number of customers using a number of different firewalls, and I was wondering if anyone has any guidelines for the presentation firewall rules or any firewall conventions when it comes to documenting the rules. Ie name conventions for groups or services, or rules for the creation of groups. Or the description of a rule I know this would be hard and vary from administrator to administrator but I was wondering if there is some sort of standard? My goal is to reduce the amount of rules and make them readable.
I don't know if this will address your problem (or even if it's going to work) but I'm in the design phase of a big, but simple, perl script that is to generate config files for an IOS router, a PIX, a NOC, some Linux workstations and some OS X workstations on my networks. The idea is to have the firewall rules for, say, email generated in a single function so all the firewalls will do what I want them to and so the rules being generated will all be in the same place -- on the screen when I write the code -- so I can carefully deal with the syntax variations. And the comments are supposed to be such that a pass over the program with perldoc will generate my security policy -- the rules will be readable and the same in there, and I will (hopefully) never need to look at the actual rules on the various platforms. -- Glenn English ghe@slsware.com GPG ID: D0D7FF20
signature.asc
Description: This is a digitally signed message part
| <Prev in Thread] | Current Thread | [Next in Thread> |
|---|---|---|
| ||
| Previous by Date: | RE: Basic Windows Security Question, Reece, Terry |
|---|---|
| Next by Date: | RE: Scanning--more then one side to the argument, Steve Fletcher |
| Previous by Thread: | Firewall rules standards, Tran, Nhon |
| Next by Thread: | Basic Windows Security Question, Andrew McIntosh |
| Indexes: | [Date] [Thread] [Top] [All Lists] |