Cabletron Systems E2100 Specifikace

Procházejte online nebo si stáhněte Specifikace pro Sítě Cabletron Systems E2100. Cabletron Systems E2100 Specifications Uživatelská příručka

  • Stažení
  • Přidat do mých příruček
  • Tisk
  • Strana
    / 233
  • Tabulka s obsahem
  • ŘEŠENÍ PROBLÉMŮ
  • KNIHY
  • Hodnocené. / 5. Na základě hodnocení zákazníků

Shrnutí obsahu

Strany 1 - FirewallonCD2

SuSELinuxFirewallonCD2

Strany 3 - Contents

Figure 3.47: Destination NAT for VPN ConnectionsPage 1/2 IPSec VPN TunnelFirst, the certificate for Nuremberg is selected. To do this, click ‘Select Ce

Strany 4

3Firewall Administration System (FAS)The Frankfurt branch should have full access to the internal network:Local Subnet activatedSubnet Address 192.168

Strany 5 - SuSE Linux – Firewall on CD2

1. General settingsConnection Name SalesRepsConnection Type Wait for the connection (Server Mode)Settings for PFS Setting, Key Life Time, and Key Repl

Strany 6

3Firewall Administration System (FAS)Figure 3.48: Configuration of Mail Relay — Dialog 1ISP Relay Activate this check box to forward all outgoing e-mai

Strany 7

Figure 3.49: Configuration of Mail Relay — Dialog 2With ‘Next’, complete the configuration of the mail relay.The Example, Inc., ConfigurationPage 1/2 Mai

Strany 8

3Firewall Administration System (FAS)proxy. With the netmask, this is reduced to a single computer:Local Networks 192.168.8.10/32All other parameters

Strany 9 - The SuSE Firewall on CD 2

sion 2 of SSH, the files id-dss.pub and id-rsa.pub are involved.Select them and the key appears in the list (see Figure 3.51).Figure 3.51: Import KeyEn

Strany 10

3Firewall Administration System (FAS)The Example, Inc., ConfigurationPage 1/2 Administration via SSHRemote access to the firewall should be possible onl

Strany 11 - Introduction

Figure 3.52: Specifying the NTP Time ServerAssuming you have activated the forwarding of log files for all active firewallconfigurations to the Adminhost

Strany 12

3Firewall Administration System (FAS)the window, providing a summary of the data recorded. This view is dividedas follows:SYSLOG Configuration Name of

Strany 13 - SuSE Firewall on CD 2

1IntroductionIntroductionThe importance of the Internet, the communication possibilities provided, andthe information-gathering options offered seem t

Strany 14 - System Requirements

Evaluating the Log FilesLog files often become very large, depending on the type of data recordedand the duration of recording. With the search mask of

Strany 15

3Firewall Administration System (FAS)Figure 3.53: IP Filter StatisticsBlocked Packet Report A pie chart shows the proportion of packets blockedgrouped

Strany 16 - 8 System Requirements

Domain Report This report is similar to the ‘Organization Report’, however,sorting is done according to domain extensions, such as .com.Packet Size Re

Strany 17

3Firewall Administration System (FAS)Figure 3.54: Interface StatisticsCertificate ManagementAccess the certificate management module in FAS with ‘Tools’

Strany 18 - Network Planning

Figure 3.55: List of Certificateshave them signed. You can also generate your own CA and sign your certifi-cates yourself. This is sufficient for most pu

Strany 19

3Firewall Administration System (FAS)Key size: Choose the key size here. A longer key is more difficult tohack. Choose 1024 or 2048 bits.After you have

Strany 20 - Typical Firewall Setups

Figure 3.56: Dialog for Creating CertificatesExporting CertificatesSelect ‘Certificate Management’ ➝ ‘Export Certificate’. There are three differ-ent form

Strany 21

3Firewall Administration System (FAS)Saving the ConfigurationSave your configuration by clicking ‘Configuration’ ➝ ‘Save’ or ‘Save All’. Ifyou try to lea

Strany 22

online help. To leave the file editor, select ‘Finish’ from the menu. Save yourmodifications to configuration files by pressing ‘Finish’.Testing the Config

Strany 23 - SuSE Adminhost for Firewall

3Firewall Administration System (FAS)Documenting Configuration, Tests, and Re-sultsIt is very important to document the configuration, the tests conduct

Strany 24 - Language Selection

Most companies rely on their own networks to exchange and process mission-critical information for in-house purposes, such as an intranet, databases,a

Strany 26 - Preparing the Hard Disk

4SuSE Live CD for FirewallSuSE Live CD for FirewallThe Live CD for the SuSE Firewall on CD is the executable part of the fire-wall. It is a minimal SuS

Strany 27

Using proxies and not forwarding IP packets are not enough to prevent un-desired Internet IP packets from reaching the intranet or vice versa. Thisfire

Strany 28 - Setting the root Password

4SuSE Live CD for FirewallDescriptionThe SuSE Linux Live CD for Firewall is a live file system CD from which allthe applications run directly. Theoreti

Strany 29

pppoed DSL supportfasfw FAS net filter scriptsyslogd Daemon for system loggingiptables Packet filtercron and logrotate Rotation of local log filesTo comp

Strany 30 - Manual Network Configuration

4SuSE Live CD for FirewalliptablesA typical iptables filter rule is very simple in theory. It normally consists offour parts:1. a basic operation with

Strany 31

Figure 4.1: Course of a Packet with iptablesPREROUTING, OUTPUT, and POSTROUTING. Figure 4.1 attempts to illustratethe interplay of nat and filter tabl

Strany 32

4SuSE Live CD for FirewallProtocol type: TCP, UDP, ICMPSource portDestination portICMP typeSource addressDestination addressInterface: eth0, ppp0, etc

Strany 33

ICMP Because ICMP packets do not use any port numbers, other selectioncriteria must be used. A list of possible parameters can be obtainedwith the com

Strany 34

4SuSE Live CD for FirewallSubsequent Treatment of Packets (Targets)After a packet has been successfully identified, a rule must know what itshould do w

Strany 35

1Introductionfirewalls is to fend off attacks directed at your intranet as well as to regulate andprotect clients on your LAN by imposing an access pol

Strany 36

Figure 4.2: Comparing IPSec and SSLthe network can be encrypted as well as the communication between singlecomputers or subnetworks.It is no problem t

Strany 37

4SuSE Live CD for Firewallonly valid for a short period. If necessary, a rekey process can be started whilethe connection still exists to replace the

Strany 38 - The User fwadmin for the FAS

SquidSquid is an HTTP proxy that offers extensive configuration options. Con-trol over the network clients’ access to the web is implemented by means o

Strany 39 - Upgrade to the VPN Edition

4SuSE Live CD for FirewallExternal to InternalTo operate an FTP server, define the settings in this part of the module toenable access from the Interne

Strany 40 - 32 Upgrade to the VPN Edition

with an ext2 file system and contain the label "SuSE-FWFloppy". Without thislabel, the configuration floppy is not recognized. The FAS (Firewal

Strany 41 - System (FAS)

4SuSE Live CD for FirewallIf necessary, additional options can be passed to the module, such asthe IRQ or the IO addresses of the hardware used. Lines

Strany 42 - Using the FAS

/etc/rc.config SuSE Linux central configuration file./etc/rc.config.d/ This directory contains files used when services arestarted, for example:/etc/rc.co

Strany 43

4SuSE Live CD for FirewallCautionNo password may be specified for any existing users apart fromroot. Do not change this file.Caution/etc/squid.conf Confi

Strany 44 - Creating a New Configuration

/opt the contents of the /opt directory on the configuration floppy arecopied to the running system in /opt. The user can store his files inthis director

Strany 45

5IPsec Client on Windows XP and Windows 2000IPsec Client on Win-dows XP and Windows 2000You can configure the connection manually with the program ipse

Strany 46 - Internet

our case, is based on the concept of an application-level gateway combined withIP packet filtering. The firewall’s routing and gateway capabilities are

Strany 47 - The Headquarters in Nuremberg

to connect to Windows 2000. The ServicePack2 is available from http://www.microsoft.com/windows2000/downloads/servicepacks/sp2/sp2lang.asp.For Windows

Strany 48 - The Branch in Munich

5IPsec Client on Windows XP and Windows 2000Importing a Root CertificateRight-click ‘Trusted Root Certificates’. In the drop-down menu, select ‘AllTasks

Strany 49 - Configuring the Base Setup

Editing ipsec.confGo to the directory C:\ProgramFiles\IPsec. Open the file ipsec.confwith an editor. Adjust the data following the syntax in example 6.

Strany 50 - 42 Using the FAS

5IPsec Client on Windows XP and Windows 2000Closing the ConnectionTo deactivate the IPsec filters and the tunnel, enter IPSEC.exe -delete.Create deskto

Strany 52 - 44 Using the FAS

6Implementing the FirewallImplementing the FirewallOn the Adminhost, you created a configuration for the Live CD using FAS ormanually created a configur

Strany 53

Requirements for Successful ImplementationFirst, check to see if your host boots using the configuration set up. Also seeif the selected services start

Strany 54 - 46 Using the FAS

6Implementing the Firewalland process requests properly. Adminhost tools are available on the firewallfor these purposes (see 2 on page 15), such as nm

Strany 55

External TestingTest externally to see if the available services are working. For instance, ifyou can send e-mails to the internal network. You should

Strany 56 - 48 Using the FAS

7HelpHelpIn this chapter, find information about creating a setup concept for a firewallsolution in your network using the SuSE Firewall on CD. Also find

Strany 57 - ↵ or click ‘Add’ af

1IntroductionELSA Quickstep 1000 PCIGeneric HFC 2BDSO PCISCSI Host Adapters:53c7,8xx: NCR 53c7,8xx (old driver)AM53C974: AM53/79C974BusLogic: BusLogic

Strany 58 - 50 Using the FAS

TroubleshootingFind help here if the Adminhost cannot be installed or if the Live CD is notbooting.Problems Installing the AdminhostIf you have troubl

Strany 59 - Page 3/5 of the Base Setup

7HelpIs external access to available resources not functioning? Which servicesare affected? Should the resources really be accessible?Test, using ps,

Strany 60 - 52 Using the FAS

Recognizing an IntrusionFirst, understand which actions are defined as intrusions. Unfortunately, itis normal these days that a host connected to the I

Strany 61 - IP Forward

7HelpList all running processes with ps and search for processes that do nottypically occur in normal firewall operation.Draw up a process table when s

Strany 62 - Destination NAT

External AttacksInform the system administrator responsible for the address block (via post-master or the domain’s abuse address). The report of an in

Strany 63 - ICMP to Firewall

7HelpExamples:Log in to the console.Examine the log files for messages of the IP filter.Search for certain unusual IP addresses (frequently occurring re

Strany 64 - 56 Using the FAS

Recommended ReadingD. Brent Chapman & Elizabeth D. Zwicky: Building Internet Firewalls,2nd edition, O’Reilly 2000.Maximum Linux Security, SAMS 199

Strany 65

8Suppor t, Maintenance, and Patch ManagementSupport, Maintenance,and Patch ManagementMaintenanceWith SuSE Maintenance, always have the most up-to-date

Strany 66 - 58 Using the FAS

Patches for the Admin CDThere are two possibilities here:Via the SuSE Maintenance WebLog in to the SuSE Maintenance Web and download patches individua

Strany 67 - Kernel Runtime Setup

8Suppor t, Maintenance, and Patch ManagementAdmin CD, download the patches via the SuSE Maintenance Web and burnthe ISO file to a CD. Find instructions

Strany 68 - System Logging

psi240i: PSI-240iqlogicfas: Qlogic FASqlogicfc: QLogic ISP 2100 SCSI-FCPqlogicisp: QLogic ISP 1020qlogicpti: PTI Qlogic ISP Driverseagate: Seagate ST-

Strany 69 - DNS Forwarder

speed sets the speed of the burning process-eject ejects the CD after burning is completedFind more options in the man page for cdrecord (man cdrecord

Strany 70 - 62 Using the FAS

8Suppor t, Maintenance, and Patch ManagementMail:Address: SuSE Linux AG— Support —Deutschhernnstr. 15-19D-90429 NürnbergProcessing: weekdaysCommercial

Strany 71 - FTP Proxy — External

D-90429 NürnbergTel: +49-911-740-53-0Fax: +49-911-740-53-479E-mail: [email protected] by our Regional Service Centers in Germany and outside, as

Strany 72 - 64 Using the FAS

8Suppor t, Maintenance, and Patch ManagementFeedbackWe always appreciate your tips, hints, and problem descriptions. We willhelp you if your problem i

Strany 73

[email protected] — Discussion of security issues in [email protected] — Announcement of security-related errors and upd

Strany 74 - FTP Proxy — Internal

ADNS — Domain Name ServiceDNS — Domain Name ServiceDNS (Domain Name Service) is needed to resolve domain and host namesinto IP addresses. This chapter

Strany 75

Starting the Name Server BINDThe name server BIND is already preconfigured in SuSE Linux, so you caneasily start it right after installing the distribu

Strany 76 - 68 Using the FAS

ADNS — Domain Name Serviceoptions {directory "/var/lib/named";forwarders { 10.11.12.13; 10.11.12.14; };listen-on { 127.0.0.1; 192.168.0.99;

Strany 77 - Generic TCP Proxy

};zone "0.0.127.in-addr.arpa" in {type master;file "127.0.0.zone";};zone "." in {type hint;file "root.hint";};

Strany 78 - 70 Using the FAS

ADNS — Domain Name Serviceallow-query 127.0.0.1; 192.168.1/24; ; defines the networks from whichclients can post DNS requests. The /24 at the end is an

Strany 79

1Introductiondepca: DEPCA,DE10x,DE200,DE201,DE202,DE422dgrs: Digi Intl. RightSwitch SE-Xdmfe: DM9102 PCI Fast Ethernete100.o: EtherExpress PRO/100 (In

Strany 80 - 72 Using the FAS

Zone Entry Structurezone "my-domain.de" in{type master;file "my-domain.zone";notify no;};File 11: Zone Entry for my-domain.deAfter

Strany 81

ADNS — Domain Name Servicemasters { 10.0.0.1; }; This entry is only needed for slave zones. It specifiesfrom which name server the zone file should be t

Strany 82 - 74 Using the FAS

Line 1: $TTL defines the standard TTL that applies for all the entries in thisfile, here 2 days. TTL means “time to live”.Line 2: The SOA control record

Strany 83 - Defining ACLs

ADNS — Domain Name ServiceLine 9: The IN NS specifies the name server responsible for this do-main. The same is true here that gateway is extended to g

Strany 84 - 76 Using the FAS

Line 1: $TTL defines the standard TTL that applies to all entries here.Line 2: ’Reverse lookup’ should be activated with this file for the network192.16

Strany 85 - Arranging ACLs

BProxy Server: SquidProxy Server: SquidThe following chapter describes how caching web sites assisted by a proxyserver works and what the advantages o

Strany 86 - 78 Using the FAS

What is a Proxy Cache?Squid acts as a proxy cache. It behaves like an agent that receives requestsfrom clients, in this case web browsers, and passes

Strany 87

BProxy Server: SquidMultiple Caches“Multiple caches” means configuring different caches so that objects can beexchanged between them, reducing the tota

Strany 88 - and ‘String’ are optional

The question remains as to how long all the other objects stored in the cacheshould stay there. To determine this, all objects in the cache are assign

Strany 89 - Access Configuration

BProxy Server: Squidrequests per second = 1000 / seek timeSquid enables more disks to be used simultaneously, increasing the numberof requests per sec

Strany 90 - 82 Using the FAS

smc9194: SMC 9194tlan: Compaq Netelligent 10/100/NetFlex 3tulip: DEC Tulip (DC21x4x) PCIvia-rhine: VIA VT86c100A Rhine-IIwd: Western Digital WD80x3yel

Strany 91

time of a hard disk, about 10 milliseconds, with the 10 nanoseconds accesstime of the newer RAM memories)Every object in RAM memory has a size of 72 b

Strany 92 - IPsec VPN Tunnel

BProxy Server: Squidproxy in the browser. To allow all users to access Squid and thus the In-ternet, change the entry in the configuration file /etc/squ

Strany 93 - General Settings

If you have updated an earlier Squid version, it is recommended to edit thenew /etc/squid.conf and only apply the changes made in the previousfile. If

Strany 94 - 86 Using the FAS

BProxy Server: Squidcache_store_log /var/squid/logs/store.log path for log messageThese three entries specify the path where Squid will log all of its

Strany 95 - IP Filter

Squid will make a note of the failed requests then refuse to issue newones, although the Internet connection has been reestablished. In a casesuch as

Strany 96 - 88 Using the FAS

BProxy Server: Squidshould always be http_access deny all. In the following example,the localhost has free access to everything while all other hosts

Strany 97

ident_lookup_access allow hacl_namei With this, you will manage to havean ident request run through for all ACL-defined clients to find outeach user’s i

Strany 98 - ➝ ‘Create Certificate’:

BProxy Server: SquidKernel ConfigurationFirst, make sure that the proxy server’s kernel has support for transparentproxies. Otherwise, add this option

Strany 99

SquidGuard is a free (GPL), flexible, and ultra fast filter, redirector, and “ac-cess controller plugin” for Squid. It lets you define multiple access ru

Strany 100 - 92 Using the FAS

BProxy Server: SquidNow, tell Squid to use SquidGuard. Use the following entries in the /etc/squid.conf file:redirect_program /usr/bin/squidGuardThere

Strany 101

1IntroductionSecurity PolicyThe security policy provides the basis for working with all programs, hosts,and data. In addition, it outlines how to guar

Strany 102 - Configuring the Mail Relay

Another powerful cache report generator tool is SARG (Squid Analysis Re-port Generator), included in series n. Further information on this can befound

Strany 103

CNetwork SecurityNetwor k SecurityThis chapter provides detailed information about several aspects of networksecurity. It begins with information abou

Strany 104 - 96 Using the FAS

Masquerading and FirewallsOwing to its outstanding network capabilities, Linux is becoming morewidespread as a router operating system for dial-up or

Strany 105 - Administration via SSH

CNetwork SecurityNoteMake sure that both the broadcast addresses and the network masksare the same for all the hosts when configuring your network.Note

Strany 106 - 98 Using the FAS

For such a connection, there would be no entry in the table because, the en-try itself is only created if an internal host opens a connection with the

Strany 107 - Log File Analysis

CNetwork Securityallowed through. This gateway or proxy pretends to be the actual client ofthe server. In a sense, such a proxy could be considered a

Strany 108 - 100 Log File Analysis

For a firewall without masquerading, only set this to yes if you wantto allow access to the internal network. Your internal hosts need to useofficially

Strany 109 - The Log Files

CNetwork SecurityFor example: "172.20.0.0/16 172.30.4.2" means that all hostswhich have an IP address beginning with 172.20.x.x, along with

Strany 110 - The IP Filter Statistics

SSH — Secure Shell, the Safe AlternativeIn these times of increasing networks, accessing a remote system also be-comes more common. Regardless of the

Strany 111

CNetwork SecurityFollowing successful authentication, work from the command linethere or use interactive applications. If the local user name is diffe

Strany 112 - Mail Statistics

1st edition 2002Copyright ©This publication is intellectual property of SuSE Linux AG.Its contents can be duplicated, either in part or in whole, prov

Strany 113 - Certificate Management

Protocol icmp ftp ssh smtp http https . . .Client internal external i. e. i. e. i. e. i. e. i. e.host1 x – x – – – x – x – –host2 x – – – x – x – – –

Strany 114 - 106 Certificate Management

The SSH Daemon (sshd) — Server-SideTo work with the SSH client programs ssh and scp, a server, the SSH dae-mon, has to be running in the background. T

Strany 115 - Importing Certificates

CNetwork SecurityIt is recommended to securely archive the private and public keys stored in/etc/ssh/ externally. In this way, key modifications can be

Strany 116 - Exporting Certificates

ssh-agent, which retains the private keys for the duration of an X session.The entire X session will be started as a child process of ssh-agents. Thee

Strany 117 - Editing Configuration Files

CNetwork Securityusers in an existing SSH connection. The SMTP and POP3 host must be setto localhost for this.Additional information can be found in t

Strany 118 - Testing the Configuration

using a network linkIn all these cases, a user should be authenticated before accessing the re-sources or data in question. A web server might be less

Strany 119 - Monitoring the Firewall

CNetwork Securityserial terminals are a special case. Unlike network interfaces, they do notrely on a network protocol to communicate with the host. A

Strany 120

This is a general rule to be observed, but it is especially true for the userroot who holds the supreme power on the system. User root can take onthe

Strany 121 - SuSE Live CD for Firewall

CNetwork Securitybuddy” or “jasmine76” are easily guessed even by someone who has onlysome casual knowledge about you.The Boot ProcedureConfigure your

Strany 122 - Hardware Requirements

directory. The purpose of these files is to define special permissions, suchas world-writable directories or, for files, the setuser ID bits, which means

Strany 123 - Services on the Firewall

CNetwork Securityhave serious consequences, in particular if the program is being executedwith special privileges (see Section C on page 199).“Format

Strany 124 - 116 Services on the Firewall

1IntroductionFigure 1.2: Simple SetupFigure 1.3: Effective and Manageable Setupstops any illegal requests at the packet level. Packets allowed through

Strany 125

Network SecurityLocal security is concerned with keeping different users on one system apartfrom each other, especially from root. Network security, o

Strany 126 - 118 Services on the Firewall

CNetwork SecurityID card of some kind. This cookie (the word goes back not to ordinary cook-ies, but to Chinese fortune cookies which contain an epigr

Strany 127

posted on the security mailing lists. They can be used to target the vulnera-bility without knowing the details of the code. Over the years, experienc

Strany 128 - 120 Services on the Firewall

CNetwork SecurityFinally, we want to mention “spoofing”, an attack where packets are modifiedto contain counterfeit source data, mostly the IP address.

Strany 129

very good way to protect your systems against problems of all kinds is to getand install the updated packages recommended by security announcementsas

Strany 130 - 122 Services on the Firewall

CNetwork Securityintended to be available in the first place (the legacy problem). Openports, with the socket state LISTEN, can be found with the progr

Strany 131

the end, only you can know which entries are unusual and which arenot.Use tcp_wrapper to restrict access to the individual services run-ning on your m

Strany 132 - FTP Proxy

DYaST and SuSE Linux License TermsYaST and SuSE LinuxLicense TermsYaST 2 Copyright (c) 1995 - 2001 SuSE GmbH, Nuernberg (Germany)YaST 2 Copyright (c)

Strany 133 - The Configuration Disk

programmes are observed. The use of YaST2, even if a modified versionis used, does not exempt in particular the Licensee from the duty totake due care

Strany 134 - The Configuration Files

DYaST and SuSE Linux License Termssources and this licence in accordance with 2b. Making YaST2 or worksderived thereof available free of charge togeth

Strany 137

EThe GNU General Public LicenseThe GNU Gen-eral Public LicenseGNU General Public LicenseCopyright (C) 1989, 1991 Free Software Foundation, Inc.59 Temp

Strany 138 - Boot Parameters

the software or use pieces of it in new free programs; and that you know youcan do these things.To protect your rights, we need to make restrictions t

Strany 139 - IPsec Client on Win

EThe GNU General Public Licenseconstitute a work based on the Program (independent of having been madeby running the Program). Whether that is true de

Strany 140

whole which is a work based on the Program, the distribution of the wholemust be on the terms of this License, whose permissions for other licenseesex

Strany 141 - Installing the ipsec.exe Tool

EThe GNU General Public Licensebinary form) with the major components (compiler, kernel, and so on) of theoperating system on which the executable run

Strany 142 - Editing ipsec.conf

only way you could satisfy both it and this License would be to refrain en-tirely from distribution of the Program.If any portion of this section is h

Strany 143 - Closing the Connection

EThe GNU General Public LicenseOur decision will be guided by the two goals of preserving the free status ofall derivatives of our free software and o

Strany 144

published by the Free Software Foundation; either version 2 ofthe License, or (at your option) any later version.This program is distributed in the ho

Strany 145 - Implementing the Firewall

IndexAACLs- arranging . . . . . . . . . . . . . . . . . . . . . . . . . 77- defining . . . . . . . . . . . . . . . . . . . . . . . . . . 75Adminhost .

Strany 146 - Testing the Firewall

2SuSE Adminhost for FirewallSuSE Adminhost for FirewallIt is no easy task to administer, maintain, and monitor a firewall. Above all, theimportance of

Strany 147

- ntp.conf . . . . . . . . . . . . . . . . . . . . . . . . . 127- pam.d . . . . . . . . . . . . . . . . . . . . . . . . . . . 127- permissions . . . .

Strany 148 - Going Online

- proxy filters . . . . . . . . . . . . . . . . . . . . . . 78httpf . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 124Iifconfig

Strany 149

Rroot- password . . . . . . . . . . . . . . . . . . . . . . . . . 20routing- masquerading . . . . . . . . . . . . . . . . . . . 184RPM- security . . .

Strany 150 - Troubleshooting

upgrading- VPN . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 31users- fwadmin . . . . . . . . . . . . . . . . . . . . . . . . . . 34VVPN

Strany 151 - Detecting Attacks

After installing the SuSE Adminhost for Firewall, theFirewall Administration System (FAS) is available. The FAS is a tool with agraphical administrati

Strany 152 - 144 Detecting Attacks

2SuSE Adminhost for FirewallTab moves the focus forward an entry or selection field or a button.Shift +Tab moves the focus to the previous

Strany 153

Figure 2.1: YaST2: Keyboard Layout and Time ZoneNow test your keyboard. By clicking with the mouse or usingTab , activatethe entry line and type i

Strany 154 - External Attacks

2SuSE Adminhost for FirewallFigure 2.2: YaST2: Preparing the Hard DiskStep 2One of the following situations could occur:If the hard disk is not empty,

Strany 155 - Examples:

Once the installation starts and all requirements have been fulfilled, YaST2partitions and formats the necessary hard disk space on its own. The entire

Strany 156 - Recommended Reading

2SuSE Adminhost for FirewallNoteRemember the root password very carefully, as you cannot retrieve itlater. This password whenever you perform administ

Strany 157 - Support, Maintenance

ContentsPreface . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 11 Introduction 3SuSE Firewall on CD 2 . . . . . . . . . . . .

Strany 158 - 150 Maintenance

resolution, color resolution, and repetition rate frequency are selected for themonitor and a test screen is displayed.NoteCheck the settings before a

Strany 159

2SuSE Adminhost for FirewallFigure 2.4: YaST2: Network ConfigurationConfiguration FilesThis section provides an overview of the network configuration file

Strany 160 - Support and Services

Figure 2.5: YaST2: Configuring the Name Serverconsisting of the IP address, the fully qualified host name, and the hostname (e. g., earth) is entered in

Strany 161 - Commercial Support

2SuSE Adminhost for Firewall## networks This file describes a number of net name-to-address# mappings for the TCP/IP subsystem. It is mostly# used at

Strany 162 - SuSE Training Program

An example for /etc/host.conf is shown in File 3.## /etc/host.conf## We have named runningorder hosts bind# Allow multiple addrsmulti on# End of host.

Strany 163 - Additional Services

2SuSE Adminhost for FirewallThe “databases” available over NSS are listed in Table 2.2. In addition,automount, bootparams, netmasks, and publickey are

Strany 164 - 156 Support and Services

files directly access files, for example, to /etc/aliases.db access via a database.nis NISnisplusdns Only usable by hosts and networks as an exten-sion

Strany 165 - DNS — Domain Name Service

2SuSE Adminhost for Firewall# /etc/resolv.conf## Our domainsearch cosmos.com## We use sun (192.168.0.1) as name servername server 192.168.0.1# End of

Strany 166 - Starting the Name Server BIND

/etc/init.d/nfsserverStarts the NFS server./etc/init.d/sendmail Controls the sendmail process dependingon the configuration in /etc/rc.config./etc/init

Strany 167

2SuSE Adminhost for FirewallAssign a password for the firewall admin user here. This password must beat least five characters in length. In the next scr

Strany 168

3 Firewall Administration System (FAS) 33Logging in as fwadmin . . . . . . . . . . . . . . . . . . . . . . . . . . . 34Starting the Firewall Administr

Strany 169

Then start the YaST2 Control Center and select ‘Install Patch CD’. Follow theinstructions there.When the installation is finished, restart the FAS daem

Strany 170 - Zone Entry Structure

3Firewall Administration System (FAS)Firewall AdministrationSystem (FAS)FAS is the graphical administration interface used to create the configurationfl

Strany 171

Logging in as fwadminAfter installation, the system boots to the graphical login. Log in here as theuser fwadmin and use the corresponding password. T

Strany 172

3Firewall Administration System (FAS)Figure 3.2: Creating a New Configurationon CD and, for this reason, is checked for its suitability with the progra

Strany 173

Figure 3.3: Creating a New AccountCreating a New ConfigurationA configuration is created on the inital login. To create additional new con-figurations, s

Strany 174 - For More Infor mation

3Firewall Administration System (FAS)Figure 3.4: Starting a New ConfigurationKernel Runtime Setup (kernel configuration)System Logging (settings for log

Strany 175 - Proxy Server: Squid

SSH Admin Login (login for the administrator with SSH)Time Synchronization (configuration of xntpd to synchronize computertime with a time server)Examp

Strany 176 - What is a Proxy Cache?

3Firewall Administration System (FAS)The SetupExample, Inc., an online bookshop with its headquarters in Nuremberg, has150 staff. It operates branches

Strany 177

80.80.80.1. The DNS service is available from the provider under the IPaddresses 123.123.123.123 and 123.123.123.124. The following entrieshave alread

Strany 178

3Firewall Administration System (FAS)Network PoliciesHeads of department in each branch should have full access to the Internet,but all other staff ma

Strany 179

Log File Analysis . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 99The Log Files . . . . . . . . . . . . . . . . . . . . . . . . . . .

Strany 180 - Starting Squid

BasicsIn ‘Basics’, either disable the root password completely (default) or set it.As a safety precaution, repeat the root password (see Figure 3.7).

Strany 181

3Firewall Administration System (FAS)Figure 3.8: Configuring the Hard DiskDisk Swap Space: Size of the swap partition, such as 128 MFurther Options Act

Strany 182

Figure 3.9: Network Interfaces1. Make these settings in the ethernet dialog (Figure 3.11 on the facingpage):Interface Names are automatically allocate

Strany 183

3Firewall Administration System (FAS)Figure 3.10: Selecting Network InterfacesFigure 3.11: Ethernet Interface2. The configuration dialog for DSL is div

Strany 184 - Options for Access Controls

conf for DSL. This file is involved with the resolution of hostnames by the resolver library and contains the domain of the hostand the IP address of t

Strany 185

3Firewall Administration System (FAS)Figure 3.12: ISDN Configuration — Part 1Interface’s Phone Number (MSN) Enter the phone number of theISDN device (M

Strany 186

Figure 3.13: ISDN Configuration — Part 2RoutingIn a dialog like Figure 3.14 on the next page), view, create, and modifyroutes. ‘Add’ creates a new rout

Strany 187 - Squid and Other Programs

3Firewall Administration System (FAS)Figure 3.14: Routing DialogNetmask The relevant netmask.Interface Select the interface to use.Save your settings

Strany 188

Figure 3.15: RoutingIn the next entry line, the search lists are specified, for example,your-company-inc.com.If you now click ‘Finish’, the base configu

Strany 189

3Firewall Administration System (FAS)Figure 3.16: Host and Domain ConfigurationOnly entire hard disks can be used. Individual partitions cannot be confi

Strany 190 - More Information on Squid

5 IPsec Client on Windows XP and Windows 2000 131Exporting the Required Certificates . . . . . . . . . . . . . . . . . . . . . 131Importing the Certific

Strany 191 - Networ k Security

Now the network card (eth1) leading to the DMZ is configured. It shouldbe responsible for a subnet of the public IP addresses. How this subnet ismade a

Strany 192 - Masquerading and Firewalls

3Firewall Administration System (FAS)Firewall host name: fw-nbgFirewall domain: example.comAs the name server, the firewall should use the internal DNS

Strany 193 - Network Security

Figure 3.17: IP Forward DialogMasqueradingThe same entry fields are available in ‘Masquerading’ (see Figure 3.18 on thenext page). Masquerading is a sp

Strany 194 - Firewalling Basics

3Firewall Administration System (FAS)Figure 3.18: Masquerading DialogDestination Port For ‘From:’, enter the destination port. For ‘To:’, define aserie

Strany 195

Figure 3.19: Dialog for Destination NATSource Address Enter the source IP address.Destination Address Select the destination address.ICMP Select the m

Strany 196

3Firewall Administration System (FAS)Figure 3.20: Dialog for ICMPAddress the internal DNS server from the DMZProtocol UDPLocal address 192.168.8.8/255

Strany 197

POP3 access to the mail server for clients from the internal net-workProtocol TCPLocal address 192.168.10.0/255.255.255.0Remote address 192.168.8.10fr

Strany 198 - The ssh Program

3Firewall Administration System (FAS)Protocol TCPLocal address 192.168.10.0/255.255.255.192Remote address 0.0.0.0from Port 1to Port 65535Protocol UDPL

Strany 199

Figure 3.21: Kernel Runtime SettingsSystem LoggingIn this dialog, shown in Figure 3.22 on the next page, configure the behav-ior of the Syslog daemon.

Strany 200

3Firewall Administration System (FAS)Figure 3.22: Settings for Syslog Daemonnation for the log files: 192.168.10.254. ‘Enable Log and Traffic Evalua-tio

Strany 201

8 Support, Maintenance, and Patch Management 149Maintenance . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 149Accessing the SuSE Ma

Strany 202

Figure 3.23: DNS Configurationrules generated automatically and specify the IP addresses of the hosts towrite to the file hosts.allow.The Example, Inc.,

Strany 203 - Security and Confidentiality

3Firewall Administration System (FAS)Figure 3.24: DNS Access ConfigurationPage 2/2 of the DNS Configuration‘Configure IP filter rules automatically’ must

Strany 204

Figure 3.25: Configuration of the FTP ServerFTP proxy port Port on which the FTP proxy is addressed, normally port21. Viewed from the outside, this tur

Strany 205

3Firewall Administration System (FAS)IP address of the FTP server Enter the IP address of the FTP server locatedin the intranet or in the DMZ.FTP serv

Strany 206 - Passwords

You will not expect many clients to want access to the FTP service at thesame time. To avoid an overloaded line, the maximum number of clientswho can

Strany 207

3Firewall Administration System (FAS)Figure 3.27: Configuration of the Internal FTP ProxyPort reset PASV By default, this check box is activated, so pa

Strany 208 - File Race Conditions

In the second mask, shown in Figure 3.28), configure access to the internalFTP proxy. By default, automatic generation of filter rules is activated. Sel

Strany 209

3Firewall Administration System (FAS)Page 2/2 Internal FTP Proxy ConfigurationIn this module, the filter rules are also generated automatically. The int

Strany 210

Figure 3.29: Configuration of the Generic Proxyand asterisk (‘*’). The wild card ‘?’ stands for any character at all. Aster-isk ‘*’ represents any numb

Strany 211

3Firewall Administration System (FAS)Figure 3.30: Redirect Settings for rinetdThe Example, Inc., ConfigurationGeneric TCP ProxyIn Example, Inc., new sa

Strany 212 - DoS — Denial of Service

Kernel Configuration . . . . . . . . . . . . . . . . . . . . . . . . . . 179Configuration Options in /etc/squid.conf . . . . . . . . . . . . . . 179Squi

Strany 213

allow activatedPattern 80.80.60.*3. IP Filter ConfigurationNo further restrictions need to be made in the “IP Filter Configuration”tab. Only the standar

Strany 214

3Firewall Administration System (FAS)Figure 3.31: Configuration of the External HTTP ProxyThe Example, Inc., ConfigurationPage 1/2 HTTP Proxy — External

Strany 215

Figure 3.32: Access to the External HTTP Proxyto 0.0.0.0/0.0.0.0.Configuring the HTTP Proxy for Internal ConnectionsIn the ‘HTTP Proxy — Internal’ modu

Strany 216

3Firewall Administration System (FAS)Figure 3.33: Configuration of the Internal HTTP ProxyTransparent Proxy Because HTTP requests from clients normally

Strany 217 - YaST and SuSE Linux

Figure 3.34: Define ACLsurl_regex Details of URL address using regular expressions.proto (protocol) Specify the appropriate protocol here.src (source)

Strany 218

3Firewall Administration System (FAS)Add Add the new ACL to the list of already created ACLs.Edit If you click ‘Edit’, a window opens in which to ente

Strany 219

Define, via ‘Negate ACL’, an ACL to use in negated form.A new rule is integrated with ‘Add’. It is then be listed in the list fieldof defined ACLs.With t

Strany 220

3Firewall Administration System (FAS)Figure 3.36: Content Filter Dialogallow allows the selected tag/attribute.log creates an entry in the log file, wh

Strany 221 - The GNU Gen

makes sense to enter something else here if you have chosen ‘replcont’,‘replabort’, ‘replskip’, or ‘replendskip’ as the action. Click ‘Add’ to gen-era

Strany 222 - GNU General, Public License

3Firewall Administration System (FAS)Figure 3.37: Mime Type FilterEnter the appropriate HTTP port of the provider is entered in ‘Parent ProxyPort’. Re

Strany 223

PrefaceMany thanks to Jürgen Scheiderer, Carsten Höger, Remo Behn, Thomas Biege,Roman Drahtmüller, Marc Heuse, and Stephan Martin.The SuSE Firewall on

Strany 224

Figure 3.38: Configuration of the Internal HTTP ProxyProxy Mode activatedCache activatedMB Cache 1000TipTransparent Proxy and CachingBecause a transpar

Strany 225

3Firewall Administration System (FAS)Figure 3.39: Access to the Internal HTTP ProxyThe values for the ACL are entered by selecting them then editing t

Strany 226

Page 7/7 HTTP Proxy — InternalThe proxy should only be used by clients from the internal network. For thisreason, access is restricted to this network

Strany 227 - No Warranty

3Firewall Administration System (FAS)Figure 3.40: Select the Local CertificateGeneral SettingsThis dialog is shown in Figure 3.42 on page 87. Assign a

Strany 228

Figure 3.41: Available CertificatesVPN ConnectionThe ‘VPN connection’ tab is shown in Figure 3.43 on page 88. Under ‘Lo-cal Configuration’, activate the

Strany 229

3Firewall Administration System (FAS)Figure 3.42: VPN: General SettingsA shared key is a random string. Quotation marks (") may not occur in thes

Strany 230 - 222 Index

Figure 3.43: VPN ConnectionTo define a rule, first select the transmission protocol: tcp, udp, or icmp. Ifyou select tcp or udp, you only need to specif

Strany 231

3Firewall Administration System (FAS)Figure 3.44: Authentication for a VPN ConnectionWhen satisfied with all the dialogs, click ‘Ok’.Information about

Strany 232 - 224 Index

Figure 3.45: Filter Rules for a VPN ConnectionCommon Name RootCAE-mail Address [email protected] unit edvOrganization Example, Inc.Local

Strany 233

3Firewall Administration System (FAS)Figure 3.46: Masquerading for a VPN ConnectionCommon Name Firewall-nbgE-mail Address [email protected]

Komentáře k této Příručce

Žádné komentáře