5.1 firewall access rules

Source: Internet
Author: User

Some enterprises use fixed IP addresses, such as the Public IP address area issued by the ISP, DMZ servers, and one-to-one NAT servers. To enable services for users on the Internet, they must use fixed IP addresses. Although it is beneficial to make public, it is relatively easy to become the target of malicious attacks. Therefore, if the enterprise network has servers or computers configured in this way, it must be protected first.
To protect the public IP server or computer, the first thing to do is to disable all the network ports except the TCP/UDP ports to provide services to avoid server attacks. For example, to provide a web server, you only need to retain the port 80 service for external access, and other services are closed. In addition, if you can restrict the open service to only specific users, such as users in other branches, you can only allow specific users to access the service, reducing the possibility of attacks again.
On the Qno no vro, this function can be configured using the network access rules and regulations tools in the vro. The access rules can be filtered based on different conditions, for example, you can set whether the inbound and outbound directions of packets are from internal to external, or from external to internal, or set the user's IP location, destination IP location, IP communication protocol type and other conditions for control, managers can set according to the actual needs.
No. There are default network access rules in the vro product. network administrators can choose to disable (deny) or allow (allow) to adjust users' access to the Internet. The administrator can customize access rules and go beyond the default access condition rules of the vro. When the rule is confirmed, it is determined from the first to the last 1-2-3 .... Rules are judged in sequence, so the order before and after access rules must be considered in the configuration plan to avoid the failure of the function you want to enable or disable.

Figure 1
Figure 1:Access rule setting is the most basic tool to block unnecessary access. For servers that use public IP addresses, it is also a basic item that must be set. Reducing access not only reduces the workload of routers, but also increases Intranet security.
For computers or internal servers that use NAT to generate private IP addresses, or virtual IP addresses, you must configure Intranet users. The main purpose is to control Intranet users' Internet access behaviors to prevent employees from reducing Internet productivity or bringing unnecessary viruses or attacks. This is necessary for many network administrators. Configure the group function to configure different access permissions for personnel in different departments. For example, the business department allows Internet access and the use of Skype, MSN, and emails to contact customers, while administrative staff can only contact customers by email. This control action can also save a lot of losses for many enterprises.

Contact Us

The content source of this page is from Internet, which doesn't represent Alibaba Cloud's opinion; products and services mentioned on that page don't have any relationship with Alibaba Cloud. If the content of the page makes you feel confusing, please write us an email, we will handle the problem within 5 days after receiving your email.

If you find any instances of plagiarism from the community, please send an email to: info-contact@alibabacloud.com and provide relevant evidence. A staff member will contact you within 5 working days.

A Free Trial That Lets You Build Big!

Start building with 50+ products and up to 12 months usage for Elastic Compute Service

  • Sales Support

    1 on 1 presale consultation

  • After-Sales Support

    24/7 Technical Support 6 Free Tickets per Quarter Faster Response

  • Alibaba Cloud offers highly flexible support services tailored to meet your exact needs.