11.07.2015 Views

WatchGuard Firebox System 7.0 User Guide

WatchGuard Firebox System 7.0 User Guide

WatchGuard Firebox System 7.0 User Guide

SHOW MORE
SHOW LESS

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

Chapter 11: Intrusion Detection and PreventionLogging and notification for blocked sitesFrom the Blocked Sites dialog box:1 Click Logging.The Logging and Notification dialog box appears.2 In the Category list, click Blocked Sites.3 Modify the logging and notification parametersaccording to your security policy preferences.For detailed instructions, see “Customizing Logging andNotification by Service or Option” on page 215.Blocking PortsYou can block ports to explicitly disable external networkservices from accessing ports that are vulnerable as entrypoints to your network. A blocked port setting takes precedenceover any of the individual service configuration settings.Like the Blocked Sites feature, the Blocked Ports featureblocks only packets that enter your network through theexternal interface. Connections between the optional andTrusted interfaces are not subject to the Blocked Ports list.You should consider blocking ports for several reasons:• Blocked ports provide an independent check forprotecting your most sensitive services, even whenanother part of the firewall is not configured correctly.• Probes made against particularly sensitive services canbe logged independently.• Some TCP/IP services that use port numbers above1024 are vulnerable to attack if the attacker originatesthe connection from an allowed well-known servicewith a port number below 1024. These connections canbe attacked by appearing to be an allowed connectionin the opposite direction. You can prevent this type ofattack by blocking the port numbers of services whoseport numbers are under 1024.188 <strong>WatchGuard</strong> <strong>Firebox</strong> <strong>System</strong>

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!