x
login about faq

How I secure my firewall properly?

What are the general best practices when it comes to securing a firewall?

more ▼

asked Oct 19 at 05:40 PM

mitchp\'s gravatar image

mitchp ♦♦
1.3k 117 140 277

(comments are locked)
10|600 characters needed characters left

2 answers: sort voted first

Always work from a Incoming > Deny All start. This means if you didn't ask for it, it doesn't come through. Then, its recommended to get a proper firewall device that can perform UTM and set up IPS policies to scan your traffic for viruses and other potential exploits and hazards. Fortigate is my vendor of choice, we've got two running in a high availability cluster, and they're simply flawless. From there, simply create the forwards and policies needed to allow traffic to inbound services. Also, there are various precautions you should take, like making a policy so no outbound traffic for port 25 traffic can come from workstations (if you've got an exchange server) this keeps some viruses from using your systems as spamhosts and blasting out spam, getting your MTA record trashed. A free alternative to an appliance is Untangle, but its a lot more difficult to set up for a non-experienced user.

more ▼

answered Nov 30 at 06:13 PM

Jaguar\'s gravatar image

Jaguar
182 1 24

(comments are locked)
10|600 characters needed characters left

Only open ports needed for inbound access, such as email, to the servers that need that port. Same thing for outbound traffic. Don't allow any direct traffic from the internet to your main lan.

more ▼

answered Nov 19 at 05:43 PM

gdoran\'s gravatar image

gdoran
0

(comments are locked)
10|600 characters needed characters left
Your answer
toggle preview:

Up to 2 attachments (including images) can be used with a maximum of 524.3 kB each and 1.0 MB total.

Follow this question

By Email:

Once you sign in you will be able to subscribe for any updates here

By RSS:

Answers

Answers and Comments

Topics:

x59
x16
x5

asked: Oct 19 at 05:40 PM

Seen: 1543 times

Last Updated: Oct 19 at 05:40 PM

powered by AnswerHub - Enterprise Social Q&A