Acknowledgments |
|
xvii | |
Preface |
|
xix | |
|
Internetwork Security Overview |
|
|
1 | (10) |
|
|
10 | (1) |
|
|
11 | (12) |
|
|
11 | (1) |
|
|
12 | (1) |
|
|
13 | (9) |
|
|
13 | (1) |
|
|
13 | (1) |
|
|
14 | (2) |
|
|
16 | (1) |
|
|
17 | (1) |
|
|
18 | (1) |
|
|
19 | (1) |
|
|
19 | (1) |
|
|
20 | (1) |
|
|
20 | (1) |
|
|
21 | (1) |
|
|
22 | (1) |
|
|
22 | (1) |
|
|
22 | (1) |
|
|
23 | (12) |
|
|
23 | (1) |
|
Security Policy Development |
|
|
24 | (5) |
|
|
24 | (2) |
|
|
26 | (1) |
|
|
26 | (1) |
|
|
27 | (1) |
|
|
27 | (1) |
|
|
27 | (1) |
|
|
27 | (1) |
|
|
27 | (1) |
|
|
27 | (1) |
|
|
28 | (1) |
|
|
28 | (1) |
|
|
28 | (1) |
|
|
28 | (1) |
|
Typical Security Policies |
|
|
29 | (3) |
|
|
29 | (1) |
|
|
29 | (1) |
|
|
30 | (1) |
|
|
30 | (1) |
|
|
30 | (1) |
|
|
30 | (1) |
|
|
30 | (1) |
|
Hardware Distribution Ltd. |
|
|
30 | (1) |
|
|
31 | (1) |
|
|
31 | (1) |
|
|
31 | (1) |
|
|
31 | (1) |
|
|
31 | (1) |
|
|
32 | (1) |
|
|
32 | (1) |
|
|
32 | (1) |
|
|
32 | (1) |
|
|
32 | (1) |
|
|
32 | (2) |
|
Premises Access Procedure |
|
|
32 | (1) |
|
|
33 | (1) |
|
Random Policy Adherence Testing |
|
|
33 | (1) |
|
Addition of New Devices to the Internetwork |
|
|
33 | (1) |
|
New Employee Security Induction |
|
|
33 | (1) |
|
Employee Departing Company |
|
|
33 | (1) |
|
Auditing of Protocols in Use |
|
|
33 | (1) |
|
|
33 | (1) |
|
|
34 | (1) |
|
|
34 | (1) |
|
Computer/Information Theft |
|
|
34 | (1) |
|
Internetworking Security Breach |
|
|
34 | (1) |
|
|
34 | (1) |
|
Policing the Security Domain |
|
|
35 | (8) |
|
Knowing Your Security Domain |
|
|
35 | (2) |
|
|
37 | (1) |
|
|
37 | (3) |
|
|
40 | (1) |
|
|
41 | (2) |
|
|
43 | (10) |
|
|
43 | (1) |
|
|
44 | (3) |
|
|
44 | (2) |
|
Application Layer Gateways |
|
|
46 | (1) |
|
|
47 | (1) |
|
|
47 | (4) |
|
FireWall-1 Next Generation |
|
|
50 | (1) |
|
|
51 | (2) |
|
|
53 | (12) |
|
|
53 | (3) |
|
Distributed Enterprise Management |
|
|
56 | (1) |
|
|
56 | (2) |
|
Third-Party Integration---OPSEC |
|
|
58 | (1) |
|
Virtual Private Network---VPN |
|
|
59 | (1) |
|
|
59 | (1) |
|
|
60 | (1) |
|
|
60 | (1) |
|
|
61 | (1) |
|
|
62 | (1) |
|
|
63 | (1) |
|
|
63 | (2) |
|
|
65 | (22) |
|
|
65 | (2) |
|
Hardening the Windows NT OS |
|
|
65 | (2) |
|
|
67 | (9) |
|
|
67 | (7) |
|
FireWall-1 GUI Installation |
|
|
74 | (2) |
|
|
76 | (1) |
|
|
76 | (4) |
|
|
79 | (1) |
|
Solaris FireWall-1 Installation |
|
|
80 | (4) |
|
|
80 | (1) |
|
FireWall-1 Installation Configuration |
|
|
81 | (1) |
|
|
81 | (1) |
|
|
81 | (1) |
|
|
82 | (1) |
|
Configuring Remote Modules |
|
|
82 | (1) |
|
SMTP, SNMP Extension, and Group Configuration |
|
|
82 | (1) |
|
IP Forwarding and Default Filtering |
|
|
82 | (1) |
|
Certificate Key Generation |
|
|
83 | (1) |
|
Solaris GUI Client Installation |
|
|
83 | (1) |
|
Solaris Uninstall Procedure |
|
|
83 | (1) |
|
|
84 | (2) |
|
|
84 | (1) |
|
|
84 | (1) |
|
Local Filesystem New Package Addition |
|
|
84 | (1) |
|
|
85 | (1) |
|
|
86 | (1) |
|
|
87 | (28) |
|
|
88 | (8) |
|
|
89 | (4) |
|
|
93 | (1) |
|
|
94 | (1) |
|
|
94 | (1) |
|
|
95 | (1) |
|
|
95 | (1) |
|
|
96 | (1) |
|
|
96 | (1) |
|
|
96 | (1) |
|
|
96 | (1) |
|
|
96 | (11) |
|
|
98 | (2) |
|
|
100 | (1) |
|
|
100 | (1) |
|
|
101 | (1) |
|
|
101 | (2) |
|
|
103 | (1) |
|
|
103 | (2) |
|
|
105 | (1) |
|
|
106 | (1) |
|
|
106 | (1) |
|
|
107 | (6) |
|
|
107 | (2) |
|
|
109 | (1) |
|
|
109 | (1) |
|
|
110 | (1) |
|
|
110 | (3) |
|
|
113 | (2) |
|
Object Creation and Management |
|
|
115 | (66) |
|
|
115 | (1) |
|
|
116 | (1) |
|
|
117 | (27) |
|
|
118 | (1) |
|
|
118 | (2) |
|
|
120 | (3) |
|
|
123 | (2) |
|
|
125 | (1) |
|
|
125 | (1) |
|
|
125 | (1) |
|
|
126 | (1) |
|
|
126 | (2) |
|
|
128 | (1) |
|
|
128 | (1) |
|
|
129 | (2) |
|
Bay Networks Router Setup Tab |
|
|
131 | (1) |
|
|
132 | (1) |
|
Steelhead Router Setup Tab |
|
|
132 | (1) |
|
|
133 | (1) |
|
|
133 | (1) |
|
|
133 | (1) |
|
|
134 | (2) |
|
Integrated Firewall Object |
|
|
136 | (1) |
|
Cisco Integrated Firewall |
|
|
137 | (2) |
|
Other Integrated Firewall |
|
|
139 | (1) |
|
|
139 | (1) |
|
|
140 | (2) |
|
|
142 | (1) |
|
Navigating the Network Objects Window |
|
|
143 | (1) |
|
|
144 | (6) |
|
|
145 | (1) |
|
|
146 | (1) |
|
|
146 | (1) |
|
|
147 | (1) |
|
|
147 | (1) |
|
|
148 | (1) |
|
|
148 | (1) |
|
Navigating the Service Objects Window |
|
|
148 | (2) |
|
Resources Objects Manager |
|
|
150 | (10) |
|
|
151 | (1) |
|
|
152 | (1) |
|
|
153 | (1) |
|
|
154 | (1) |
|
|
154 | (1) |
|
|
155 | (1) |
|
|
156 | (1) |
|
|
156 | (1) |
|
|
157 | (1) |
|
|
158 | (1) |
|
|
159 | (1) |
|
Navigating the Resources Objects Window |
|
|
159 | (1) |
|
|
160 | (10) |
|
|
160 | (2) |
|
|
162 | (1) |
|
|
162 | (1) |
|
|
163 | (1) |
|
|
164 | (1) |
|
|
164 | (1) |
|
|
165 | (2) |
|
|
167 | (1) |
|
|
168 | (1) |
|
Navigating the Server Objects Window |
|
|
168 | (2) |
|
|
170 | (7) |
|
|
172 | (1) |
|
|
172 | (1) |
|
|
173 | (1) |
|
|
173 | (1) |
|
|
173 | (2) |
|
|
175 | (1) |
|
|
175 | (1) |
|
Navigating the User Objects Window |
|
|
175 | (2) |
|
|
177 | (2) |
|
Navigating the Time Objects Window |
|
|
179 | (1) |
|
|
179 | (2) |
|
|
181 | (18) |
|
|
181 | (2) |
|
|
183 | (1) |
|
|
184 | (2) |
|
|
186 | (1) |
|
|
186 | (1) |
|
|
187 | (1) |
|
|
188 | (1) |
|
|
189 | (1) |
|
|
189 | (2) |
|
|
191 | (1) |
|
|
192 | (3) |
|
|
195 | (1) |
|
|
195 | (1) |
|
|
196 | (3) |
|
|
199 | (32) |
|
|
199 | (1) |
|
|
200 | (2) |
|
|
202 | (10) |
|
|
204 | (1) |
|
|
204 | (1) |
|
The Firewall Gateway Definition |
|
|
205 | (1) |
|
Local Network and Outgoing Traffic |
|
|
205 | (4) |
|
|
209 | (1) |
|
|
210 | (2) |
|
Navigating the Rulebase and Creating Rules |
|
|
212 | (12) |
|
|
213 | (1) |
|
|
213 | (1) |
|
|
214 | (1) |
|
|
215 | (1) |
|
|
216 | (1) |
|
|
216 | (1) |
|
|
217 | (1) |
|
|
217 | (2) |
|
|
219 | (1) |
|
|
219 | (1) |
|
|
220 | (1) |
|
|
220 | (2) |
|
|
222 | (1) |
|
|
223 | (1) |
|
|
223 | (1) |
|
|
224 | (1) |
|
Installing and Uninstalling the Security Policy |
|
|
224 | (3) |
|
|
224 | (1) |
|
|
225 | (1) |
|
Check the Rulebase for Consistency |
|
|
225 | (1) |
|
Install the Security Policy |
|
|
226 | (1) |
|
|
227 | (1) |
|
|
227 | (4) |
|
|
231 | (14) |
|
|
231 | (2) |
|
|
233 | (5) |
|
|
233 | (1) |
|
|
234 | (2) |
|
|
236 | (2) |
|
Authentication Implementation |
|
|
238 | (6) |
|
|
244 | (1) |
|
Network Address Translation |
|
|
245 | (10) |
|
|
246 | (3) |
|
Static Mode Implementation |
|
|
247 | (2) |
|
|
249 | (3) |
|
|
249 | (3) |
|
Issues with Network Address Translation |
|
|
252 | (1) |
|
|
253 | (2) |
|
|
255 | (24) |
|
LAB Network Configuration |
|
|
255 | (2) |
|
|
257 | (1) |
|
|
257 | (1) |
|
|
257 | (1) |
|
Firewall Object Definitions |
|
|
258 | (8) |
|
|
258 | (1) |
|
|
259 | (7) |
|
|
266 | (4) |
|
|
266 | (1) |
|
|
266 | (4) |
|
|
270 | (1) |
|
|
270 | (2) |
|
|
270 | (1) |
|
|
271 | (1) |
|
|
272 | (4) |
|
|
273 | (1) |
|
|
273 | (2) |
|
|
275 | (1) |
|
|
275 | (1) |
|
Network Address Translation |
|
|
276 | (2) |
|
|
276 | (1) |
|
|
276 | (1) |
|
|
277 | (1) |
|
|
278 | (1) |
|
|
278 | (1) |
|
|
279 | (12) |
|
|
282 | (2) |
|
Internetwork Architecture |
|
|
282 | (1) |
|
|
283 | (1) |
|
|
283 | (1) |
|
|
283 | (1) |
|
Vulnerability Exploitation |
|
|
284 | (1) |
|
Penetration of the Lab Network |
|
|
284 | (5) |
|
|
284 | (1) |
|
|
285 | (1) |
|
|
285 | (1) |
|
|
286 | (1) |
|
|
287 | (1) |
|
|
288 | (1) |
|
|
289 | (2) |
|
|
291 | (6) |
|
|
291 | (2) |
|
|
291 | (1) |
|
|
292 | (1) |
|
|
292 | (1) |
|
|
292 | (1) |
|
|
293 | (1) |
|
|
293 | (1) |
|
|
293 | (1) |
|
|
294 | (1) |
|
|
295 | (2) |
|
CCSA Objective Essentials |
|
|
297 | (14) |
|
|
298 | (2) |
|
|
298 | (1) |
|
|
298 | (1) |
|
|
299 | (1) |
|
Distributed Enterprise Management |
|
|
299 | (1) |
|
|
299 | (1) |
|
|
299 | (1) |
|
|
300 | (1) |
|
|
300 | (1) |
|
|
300 | (1) |
|
|
300 | (1) |
|
|
300 | (1) |
|
|
300 | (1) |
|
|
301 | (1) |
|
|
302 | (2) |
|
|
302 | (1) |
|
|
303 | (1) |
|
|
303 | (1) |
|
|
304 | (1) |
|
|
305 | (1) |
|
|
305 | (1) |
|
|
305 | (1) |
|
|
306 | (1) |
|
|
306 | (1) |
|
|
306 | (1) |
|
|
307 | (1) |
|
|
307 | (2) |
|
|
308 | (1) |
|
UDP Virtual Session Timeout |
|
|
308 | (1) |
|
|
308 | (1) |
|
Enable Decryption on Accept |
|
|
308 | (1) |
|
Accept VPN-1 and FireWall-1 Control Connections |
|
|
308 | (1) |
|
|
308 | (1) |
|
Accept Domain Name over UDP |
|
|
308 | (1) |
|
|
308 | (1) |
|
Accept Outgoing Packets Originating from Gateway |
|
|
308 | (1) |
|
|
308 | (1) |
|
|
309 | (2) |
APPENDIX Sample Questions |
|
311 | |
|
|
311 | (9) |
|
|
320 | (9) |
|
|
329 | (9) |
|
|
338 | (1) |
|
|
339 | (1) |
|
|
340 | |