Avocent Access Router Cyclades-PR2000 User Manual

Page 99

Advertising
background image

99

Cyclades-PR2000

Chapter 12 - Filters and Rules

Exterior Router

The exterior router is the network’s first defense against attacks. For this reason, it is reasonable to prohibit all
packets except for those explicitly allowed. This is done by choosing the

Default Scope to be Deny. Thus, ALL

desired traffic must be expressly allowed by the rules in the rule list.

Let

e-mail in

World

of P

os

sib

le

P

a

ck

e

ts

Let

e-mail out

DENY

DENY

DENY

Let Telnet

Connections Out

FIGURE 12.3 DENY AS DEFAULT SCOPE

In Figure 12.3, a conceptual equivalent of the interface is shown. All packets except those which fall into the
holes in the ball will be denied entry in to or out of the network.

Advertising