11.07.2015 Views

WatchGuard Firebox System 7.0 User Guide

WatchGuard Firebox System 7.0 User Guide

WatchGuard Firebox System 7.0 User Guide

SHOW MORE
SHOW LESS

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

Selecting Services for your Security Policy Objectives• Services that send passwords in the clear (FTP, telnet,POP) are very risky.• Services with built-in strong authentication (such asssh) are reasonably safe. If the service does not havebuilt-in authentication, you can mitigate the risk byusing user authentication with that service.• Services such as DNS, SMTP, anonymous FTP, andHTTP are safe only if they are used in their intendedmanner.• Allowing a service to access only a single internal hostis safer than allowing the service to access several or allhosts.• Allowing a service from a restricted set of hosts issomewhat safer than allowing the service fromanywhere.• Allowing a service to the optional network is safer thanallowing it to the trusted network.• Allowing incoming services from a virtual privatenetwork (VPN), where the organization at the otherend is known and authenticated, is generally safer thanallowing incoming services from the Internet at large.Each safety precaution you implement makes your networksignificantly safer. Following three or four precautionsis much safer than following one or none.Outgoing service guidelinesIn general, the greatest risks come from incoming services,not outgoing services. There are, however, some securityrisks with outgoing services as well. Control of outgoingservices helps to protect your network from hostile actswithin your organization. For example, when configuringthe outgoing FTP service, you can make it read-only and/or restrict the destination hosts that can receive such atransmission. This prevents insiders from using FTP totransmit corporate secrets to a home computer or to a rivalorganization.<strong>User</strong> <strong>Guide</strong> 115

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!