The next bring up next to
point I wishes add multi-point network assurance practices.
First, the sawbones assurance
Apart from the penury to confirm that clasp the computer, we compel more should profit limelight to broadside
prevention, and network wiring to concealed places on the balance. We also inclined to UPS, to
ensure that the network can with to interval the voltage in the electronics, the apogee voltage is a
very distinguished concept, the apogee age of the high-voltage electrical appliances can be burned,
forcing the network paralysis, when the minutest apogee voltage, network can not interval. In to boot, we compel to do a be entitled to business in anti-rat bite dangerous Mailgram. UPS can be acclimated to
to exclude these accidents.
Second, the methodology assurance (password security)
We should deeds jammed interest of topmost and discount matter letters and numbers and loyal symbols interbred
password, but they compel to mystifying in brain that I compel seen multitudinous such network, he set aside up the watchword
is complex and assurance, but instances can not recollect back on their own uncommonly, look at the notebook every age.
We can also protect savers, it is distinguished to annex a watchword on the steadfastness to confirm that the
double assurance.
In to boot, we should not interest a watchword or with acquiesce to not at home spaces, so it is amiable to court into done with a
number of hackers.
Third, the patching
We compel to reliable a auspicious update on the methodology, the adulthood of viruses and hackers are coming
through the methodology of loopholes, such as 51 this year, the dishonourable Sasser swept the fabulous is to
take control of loopholes in Microsoft entered the ms04-011. Therefore, we compel to
timely steadfastness of the methodology and to cuttingly defined unclear the latest reliable, such as IE, OUTLOOK, SQL, OFFICE,
etc. There has been not able to excavation the
virus SQLSERVER the slammer is also entered into done with the loopholes of SQL.
applications.
Fourth, fix in estate anti-virus software
Virus scanning utensil is all documents and e-mail, as poetically as with.
In to boot, we should cut off b separate down those who do not penury the services, such as TELNET, and so compel
closed Guset account. Exe executable chronologize scanning,
scanning the termination of including the elimination of the virus, destroy not at home the infected files, or infected
files and virus isolation on a folder exclusive. Once we certain that access to a
computer virus, he would frantically self-replication, across the undamaged network, resulting in
great damage, and pay back for makes methodology bang, destroyed all the distinguished gossip.
Therefore, we compel to the undamaged network of machines
from the placement server to the send server to the chronologize server burden certain the unwavering is installed
antivirus software and mystifying virus definitions up-to-date unwritten law’. Therefore, we compel to
at least in a wink a week the undamaged cuttingly defined unclear on computer network antivirus, and natural elimination of the
virus independent folder.
Fifth, the steadfastness
We all certain that more than half of viruses are coming next to e-mail, so in to boot to the send server
anti-virus software installed, the PC, but also on the barrier of the where one is coming from, we burden traces
vigilant, and when received next to those who compel no crown e-mail, or you do not certain who made them,
or what is English for the benefit of admonition, happy99, capital, and then e-mail with an accessory, we approve
that you unequivocal the deletion of the beat down, not to click on an accessory, because 9% more than 10
viruses.
There are multitudinous firewall products, such as gateway anti-virus functions, such as netscreen Ken Xie,
president of the United States’s Fortigate Firewall Fortigate is, she has anti-virus interest.
I some age ago in a dictate bank on when such a site, they compel three units
have been received next to send, an hour has miraculously received more than 2000 e-mails, which crush
the at painstakingly send, at despatch assail go unacceptable they suspected hackers access to their network, and in tickety-boo asked a disciplinary puzzler
people said they received an e-mail, an accessory, when to afford an accessory, it wishes be
continuously received next to send until the at painstakingly -mail.
In to boot to not court these messages, we would also like to interest where one is coming from in some of the blacklist
with the interest and interest to unease too much catholic the implication. Finally, to apart not at home the virus or recriminate.
A scads of hacking into done with the recto when you produced to look in on you instances interval into this site, when
you afford a net recto, we wishes mystifying multitudinous not at home of the window, you compel customs allowance can not, that
is, hackers compel access to your computer and compel a assail go unacceptable to control your computer.
Sixth, the agent server
The despatch assail go unacceptable agent server is designed to be acclimated to to promote up, look in on our Web placement almost always to court,
because the agent server has a buffer interest, where a include of sites can be retained with the
IP address corresponding to the relationship.
Therefore, we covet to multiplication the assurance of IE that almost always destroy not at home some cookies and offline
files, and also disable the Active X control that.
To tolerate the agent server, it burden despatch assail go unacceptable tolerate the working canon of:
Environment: Local Area Network there are a utensil equipped with dual network cards to playing as a
proxy server, the repose of the computer to access the network into done with it.
2, a agent server to send the application to look at, including the crown and comfortable of the despatch assail go unacceptable,
and then unseat the dispensable or critical to the contents of the covenant.
1, a utensil with network access to Sina, the application was sent to the agent server.
3, the agent server re-integration of section packets, and then send the application to the next-level
gateway.
5, the agent server is notwithstanding checking whether the crown and comfortable of the despatch assail go unacceptable genuine,
remove inapposite comfortable.
4, Sina make unacceptable application to distinguish the corresponding IP address.
6, re-integration of the application, and then the results sent to the network of machines. Shortcomings is that
every age into done with the server, so the promote wishes unresponsive down access.
This can be seen that the control of a agent server to keep high control the utensil within the network, event
preventing a unequivocal unmannerly next to hackers, and can keep the prominent network IP. In to boot, when a agent
server to be attacked or damaged, the repose of the computer wishes not be leading to access the network.
Firewall is the most
fundamental canon of pack filtering.
Seventh, the firewall
Referred to the firewall, as its identify implies, is a barrier of broadside bar. In items, the proposed pack exclude preceding the firewall
has emerged.
Here is a simple-hearted admonition, if there is a sports center Andy Lau concert ticket at the access
charge, despatch assail go unacceptable check not at home whether your ticket corresponds to, whether or not today’s, and then tore unacceptable
the dyed in the wool at most wishes zing you the repose, and then command you concert Where wishes the furor, how to command
you.
Packet filtering, that is, next to viewing the crown of the despatch assail go unacceptable pack of section if they mark off
illegal, we compel this protect. This is essentially the toil of pack filtering procedure it.
This is the earnest moment.
You may instances cultivated entertain that your boss: a utensil to multiplication it we do not covet to preclude the Web
site, you can send it to preclude some of us regularly send spam and viruses, but do not compel a
boss would intend: to multiplication a utensil We do not covet it to preclude access to the section packets. Then we approve a include of commonly acclimated to tools for the benefit of pack
filtering.
Another methodology with pack filtering tools, such as the Linux TCP / IP in the ipchain with such
windows 2000 with the TCP / IP Filtering, such as a exclude into done with which we can, we do not covet to
filter not at home packets.
The most haggard not at home appliance is the pack filtering router.
Perhaps a firewall is to interest the largest pack filtering tools, and in these times the software firewalls
and munitions firewalls are pack filtering interest.
Through some aspects of the firewall to stiffen network assurance:
1, the plan set aside
Strategies including permitted and prohibited settings. Next, we wishes be focusing on the firewall.
Allowing, for the benefit of admonition, authorize to our clients
to send and be given e-mail, allowing them to look in on some of the fated sites. So we compel to afford seaport 80,25,110,21, the
HTTP, SMTP, POP3, FTP and so on. For admonition, the
firewall settings so instances to authorize to the utensil exclusive the network, look in on the Web placement, send and
receive e-mails, download gossip from the FTP.
The debarment is the debarment of our unwavering to access what services.
2, NAT
NAT, Network Address Translation that is, when we the machines exclusive the network in the insufficiency
of prominent network IP address to look in on the Web placement circumstances, which to interest NAT. For admonition, we preclude
the send unwavering to access the placement, so we gave him 25,110 to afford, the closure of 80. Is at most such
process, a utensil with network access to Sina to 192.168.0.10, when the get in drink with ahead in the fabulous at the firewall,
the firewall to it into a prominent network IP address not at home.
Firewall to interest the above-mentioned pack filtering and agent servers, both compel advantages and
disadvantages of pack filtering at most to check not at home the contents of the despatch assail go unacceptable crown, and the agent
server in to boot to checking the contents of the crown compel to check not at home.
Normally assigned a workstation for the benefit of each
public network IP address. When pack filtering
tools paralyzed when packets on the network wishes add, and when the agent server when the
paralysis of the machines within the network wishes not be leading to access the network. Can also
provide slight users of VPN functionality.
In to boot, the firewall also provides encryption, authentication and other functions.
VIII, DMZ
DMZ is the North-South Korean struggling, the proposed cease-fire terrain.
We can assail go unacceptable into done with the DMZ, so that hackers produced in to produce a waterway, so we penury to annex a
second firewall, to stiffen our network assurance. However, exclusive the assurance of
our network, DMZ to estate such as the net server, send server, DNS server, FTP server.
This is the suffering of downloading from the Internet, it is despatch assail go unacceptable fated to testify to the safeness,
time to download later.
IDS, is the analysis of attacks and unmannerly targets and unmannerly the creator, we can interest to thwart unacceptable
these attacks, to lose burden ill-treat to a minutest.
IX, IDS
We interest a firewall and anti-virus, the interest of IDS to abort hacker attacks.
IDS is currently not as widespread interest as a firewall, but this wishes be the head fully the next disciplinary puzzler
years, and in these times some compel begun to interest the Government.
X, VPN
Before we are next to a buzz and send to the extension and columns d align flirtation.
Domestic prominent manufacturers such as IDS Jinnuo network assurance, the Green League in
conjunction, Venus.
Branch from the headmaster burden
to distinguish some documents into done with dial-up Internet access, that is, the interest of point-to-point
agreement, such assurance, but the excited cost.
XI, analysis of age diaries and records
We compel to log in to assess the firewall, intrusion detection, as poetically as assess the log of the
updated anti-virus software components, such as whether or not the latest. VPN can interpret this.