Question

What are some of the rules you should follow with packet filtering firewalls?  

What are some of the rules you should follow with packet filtering firewalls?  

0 0
Add a comment Improve this question Transcribed image text
Answer #1
  1. Editing rules offline: The filter editing tools on most system are usually minimal also we don't know how the rules will interact with the current existing ones. It is usually difficult to delete rules or add rules in middle of existing one without creating some problems. Hence it is advisable to make new rules in a simple text editor so that it is quite easy to manipulate the rule set and the load this rule set in the actual filter. For example in Cisco we use TFTP to obtain command files from a server. You can also make comments on the file which can be stripped while sending this file to the server. Most systems discard the comments in the entirety.
  2. Always reload rule set from scratch each time: One should always delete the old rule set completely and then load the new rule suet because then the administrator need not worry about how the new and the old rules might interfere with each other.
  3. Always use IP addresses and not host names: If host names or network names are specified then someone can accidentally or intentionally corrupt the name to address translation by feeding false data to DNS.
Add a comment
Know the answer?
Add Answer to:
What are some of the rules you should follow with packet filtering firewalls?  
Your Answer:

Post as a guest

Your Name:

What's your source?

Earn Coins

Coins can be redeemed for fabulous gifts.

Not the answer you're looking for? Ask your own homework help question. Our experts will answer your question WITHIN MINUTES for Free.
Similar Homework Help Questions
ADVERTISEMENT
Free Homework Help App
Download From Google Play
Scan Your Homework
to Get Instant Free Answers
Need Online Homework Help?
Ask a Question
Get Answers For Free
Most questions answered within 3 hours.
ADVERTISEMENT
ADVERTISEMENT
ADVERTISEMENT