12.07.2015 Views

Symantec™ Security Gateways Reference Guide - Sawmill

Symantec™ Security Gateways Reference Guide - Sawmill

Symantec™ Security Gateways Reference Guide - Sawmill

SHOW MORE
SHOW LESS

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

56 Understanding accessProxiesThe NBDGRAM proxyThe NNTP proxyThe NetBIOS Datagram proxy transports NetBIOS traffic over UDP port 138. The proxy modifies theNetBIOS header to contain the correct source IP address and port number as seen by the recipient of thepacket. This solves the problem of NetBIOS being unable to respond to received packets because thespecified source in the NetBIOS header is not the actual source of the UDP packet.This proxy is useful in cases where NetBIOS services need to pass through the security gateway, but somesort of non-standard routing or address hiding is in effect.Network news transfer protocol (NNTP) has existed since 1986, and NNTP news servers have long been thetargets of attacks. Much of this is because the management of news servers has, until recently, beenunauthenticated. Anyone with access to a Telnet utility can connect to a news server and type in newsarticles or commands in an attempt to corrupt the USENET newsgroups.The NNTP proxy lets the administrator regulate what articles are sent and received from news servers.Usage scenariosThere are several possible traffic patterns that the NNTP proxy can accommodate:■■■Users on the protected network accessing public news servers. You may want to filter the newsgroupsusers can access (by newsgroup name or by IP address). You may want to disable posting of new articles.You may want to authenticate users or restrict the time of day they can access newsgroups.Users on the protected network accessing internal news servers. Internal news servers get feeds fromexternal news servers. You may want to control which newsgroups are downloaded between servers andwhat time of day the downloads can occur. You may want to authenticate the external news server orallow only external news servers with specific IP addresses to feed the internal news server.Users outside of the protected network accessing internal news servers. You want to authenticate theusers because they are likely employees at home or on the road trying to access the internal newsserver.Note: The following commands are not supported by the NNTP proxy: CHECK, TAKETHIS, XINDEX,XPATH, XROVER, XTHREAD.NNTP proxy authenticationThe NNTP proxy supports only those authentication systems that do not require the proxy to interact withthe user. For example, the NNTP proxy supports gateway password and RSA SecurID authenticationschemes, but Bellcore S/Key is not supported.When news readers prompt users for names and passwords, they normally do not indicate what kind ofpassword is being requested (although the NNTP protocol gives them enough information to do so).However, it is possible to type challenge-less one-time passwords as the clear-text password, as long as theuser knows ahead of time what kind of scheme is being used. The NNTP proxy simply passes the user nameand password into whatever authentication scheme is enabled for the rule.It is also possible for both the security gateway and the news server to require authentication. The securitygateway also requires a news server to authenticate before allowing a news feed.

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!