workbook:jno-332:332_policies
Differences
This shows you the differences between two versions of the page.
Both sides previous revisionPrevious revisionNext revision | Previous revision | ||
workbook:jno-332:332_policies [2017/05/16 17:08] – k | workbook:jno-332:332_policies [2021/08/12 08:35] (current) – external edit 127.0.0.1 | ||
---|---|---|---|
Line 1: | Line 1: | ||
- | ===== 332 Security Policies ===== | + | ===== JN0-332: Junos Security Policies ===== |
** Необходимые знания по Security Policies: ** | ** Необходимые знания по Security Policies: ** | ||
*Identify the concepts, benefits and operation of security policies | *Identify the concepts, benefits and operation of security policies | ||
Line 11: | Line 11: | ||
*ALGs :!: | *ALGs :!: | ||
*Address books :!: | *Address books :!: | ||
- | *Applications | + | *Applications |
*Demonstrate knowledge of how to configure, monitor and troubleshoot security policies | *Demonstrate knowledge of how to configure, monitor and troubleshoot security policies | ||
*Policies | *Policies | ||
Line 38: | Line 38: | ||
=== Действия политики === | === Действия политики === | ||
* permit - разрешаем трафик и создаем сессии. | * permit - разрешаем трафик и создаем сессии. | ||
- | * Firewall | + | * **firewall-authenication** - прикручиваем авторизацию для доступа к какому-либо сервису ([[workbook: |
- | * ipsec tunnel - заворачиваем попавший под политику трафик в ipsec туннель (policy based ipsec). | + | [edit security policies from-zone TRUST to-zone UNTRUST] |
- | * IDP - передаем трафик на анализ системе предотвращения вторжений. | + | root@bluebox# |
- | * UTM - заворачиваем трафик в антивирус, | + | Possible completions: |
+ | + apply-groups | ||
+ | + apply-groups-except | ||
+ | > pass-through | ||
+ | > web-authentication | ||
+ | </ | ||
+ | * **tunnel** - заворачиваем попавший под политику трафик в ipsec туннель (policy based ipsec).< | ||
+ | [edit security policies from-zone TRUST to-zone UNTRUST] | ||
+ | root@bluebox# | ||
+ | Possible completions: | ||
+ | + apply-groups | ||
+ | + apply-groups-except | ||
+ | ipsec-group-vpn | ||
+ | ipsec-vpn | ||
+ | pair-policy | ||
+ | </ | ||
+ | * **destination-address** < | ||
+ | [edit security policies from-zone TRUST to-zone UNTRUST] | ||
+ | root@bluebox# | ||
+ | Possible completions: | ||
+ | < | ||
+ | + apply-groups | ||
+ | + apply-groups-except | ||
+ | drop-translated | ||
+ | drop-untranslated | ||
+ | | Pipe through a command | ||
+ | </ | ||
+ | * **application-services** | ||
+ | [edit security policies from-zone TRUST to-zone UNTRUST] | ||
+ | root@bluebox# | ||
+ | Possible completions: | ||
+ | > application-firewall | ||
+ | + apply-groups | ||
+ | + apply-groups-except | ||
+ | gprs-gtp-profile | ||
+ | gprs-sctp-profile | ||
+ | idp Intrusion detection and prevention | ||
+ | redirect-wx | ||
+ | reverse-redirect-wx | ||
+ | > uac-policy | ||
+ | utm-policy | ||
+ | </ | ||
* reject - дропаем трафик и отправляем icmp unrechable для UPD трафика и RST для TCP трафика. | * reject - дропаем трафик и отправляем icmp unrechable для UPD трафика и RST для TCP трафика. | ||
* deny - тихо дропаем трафик. | * deny - тихо дропаем трафик. | ||
Line 320: | Line 361: | ||
---- | ---- | ||
- | ===== Список используемых материалов ===== | + | ===== Полезные материалов ===== |
* [[http:// | * [[http:// | ||
+ | |||
+ | {{tag> |
workbook/jno-332/332_policies.1494943709.txt.gz · Last modified: (external edit)