Re: How to keep firewall rules clean and up-to-date
Tracy Reed <[email protected]> Wed, 27 Apr 2011 15:45:20 -0700
| Newsgroups | gmane.comp.security.firewalls.wizards |
|---|---|
| Message-ID | <[email protected]> |
On Tue, Apr 26, 2011 at 01:12:06PM +0200, Ilias - spake thusly: > What do you do to keep your firewall rules clean and up-to-date? Periodic firewall config audits. Review each rule, make sure it still has a purpose. Ideally you would search the rules whenever a box is retired but that has been difficult to enforce in my environments. Best is to have reviews regularly enough that when you see a rule for a box that has recently been retired you recognize it. I extensively comment my firewall rules also and explain why each rule is there and what it is intended to do. That makes recognizing unneeded rules much easier. Accounting on your firewall rules is nice also. If you see a rule that hasn't been hit in a while or only hit with a few packets such as might result from a SYN scan from the net you can investigate if it is needed anymore and remove it. If a server changes IP addresses we have always found it easier with our system to edit the existing rule rather than add a new one so we tend not to get duplicates rules because a system changed IP addresses. -- Tracy Reed _______________________________________________ firewall-wizards mailing list [email protected] https://listserv.icsalabs.com/mailman/listinfo/firewall-wizards
signature.asc
(application/pgp-signature, 189 B)
-----BEGIN PGP SIGNATURE----- Version: GnuPG v1.4.5 (GNU/Linux) iD8DBQFNuJyABhSTPg0d/nQRAmV3AKDAIPt2zfNr74+y7TRWe4xyRof5lgCaAsCe XB9Q2MgNkQxZVnpPYPi7kEU= =Pvy1 -----END PGP SIGNATURE-----