01.06.2014 Views

Netværkssikkerhed i firmanetværk - Prosa

Netværkssikkerhed i firmanetværk - Prosa

Netværkssikkerhed i firmanetværk - Prosa

SHOW MORE
SHOW LESS

Create successful ePaper yourself

Turn your PDF publications into a flip-book with our unique Google optimized e-Paper software.

First or Last match firewall?<br />

first<br />

match<br />

block/pass<br />

last<br />

match<br />

first eller last-match?<br />

...<br />

block ip from 10.0.0.1 to 10.0.0.2<br />

pass ip from 10.0.0.1 to 10.0.0.3<br />

pass ip from 10.0.0.1 to 10.0.0/24<br />

block ip from 10.0.0.1 to 10.0.0.5<br />

block ip from 10.0.0.1 to 10.0.0.2<br />

...<br />

block/pass<br />

Med dette regelsæt vil en first-match firewall blokere pakker fra<br />

10.0.0.1 til 10.0.0.2 - men tillade alt andet fra 10.0.0.1 til 10.0.0/24<br />

Med dette regelsæt vil en last-match firewall blokere pakker fra<br />

10.0.0.1 til 10.0.0.2, 10.0.0.1 til 10.0.0.5, 10.0.0.1 til 10.0.0.2<br />

- men ellers tillade alt andet fra 10.0.0.1 til 10.0.0/24<br />

• To typer af firewalls: First match - eksempelvis IPFW, Last match - eksempelvis PF<br />

c○ copyright 2009 Security6.net, Henrik Lund Kramshøj 229

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!