11.07.2015 Views

Improving Web Application Security: Threats and - CGISecurity

Improving Web Application Security: Threats and - CGISecurity

Improving Web Application Security: Threats and - CGISecurity

SHOW MORE
SHOW LESS

Create successful ePaper yourself

Turn your PDF publications into a flip-book with our unique Google optimized e-Paper software.

How To: Use IPSec for Filtering Ports <strong>and</strong> Authentication 781Figure 5IP Filter List dialog boxAfter creating the filter actions <strong>and</strong> filter lists, you need to create a policy <strong>and</strong> tworules to associate the filters with the filter actions. Create <strong>and</strong> apply IPSec policy1. In the main window of the Local <strong>Security</strong> Policy snap-in, right-click IPSec<strong>Security</strong> policies on Local Machine, <strong>and</strong> then click Create IP<strong>Security</strong> Policy.2. Click Next to move past the initial Wizard dialog box.3. Type MyPolicy for the IPSec policy name <strong>and</strong> IPSec policy for a <strong>Web</strong> server thataccepts traffic to TCP/80 <strong>and</strong> TCP/443 from anyone for the description, <strong>and</strong> thenclick Next.4. Clear the Activate the default response rule check box, click Next, <strong>and</strong> then clickFinish.The MyPolicy Properties dialog box is displayed so that you can edit the policyproperties.5. Click Add to start the <strong>Security</strong> Rule Wizard, <strong>and</strong> then click Next to move past theintroductory dialog box.6. Select This rule does not specify a tunnel, <strong>and</strong> then click Next.7. Select All network connections, <strong>and</strong> then click Next.8. Select Windows 2000 default (Kerberos V5 protocol), <strong>and</strong> then click Next.9. Select the MatchHTTPAndHTTPS filter list, <strong>and</strong> then click Next.10. Select the MyPermit filter action, click Next, <strong>and</strong> then click Finish.11. Create a second rule by repeating steps 5 to 10. Instead of selectingMatchHTTPAndHTTPS <strong>and</strong> MyPermit, select MatchAllTraffic <strong>and</strong> MyBlock.

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!