> From fw-1-mailinglist-owner @
com Tue Feb 11 13:44:17 1997
> X-Authentication-Warning: loudecho.us.checkpoint.com: majordom set sender to owner-fw-1-mailinglist @
com using -f
> Date: Tue, 11 Feb 1997 13:14:56 -0500
> From: John Kerr <jkerr2 @
> MIME-Version: 1.0
> To: "Jeffrey L. Oliver" <oliver @
> CC: "fw-1-mailinglist @
com" <fw-1-mailinglist @
> "firewalls @
com" <firewalls @
> Subject: Re: [FW1] rule set
> Content-Transfer-Encoding: 7bit
> Jeffrey L. Oliver wrote:
> > G'Day,
> > Is there a prefered order for the rule set in FW-1?
> > regards,
> > Jeff
> > ---------------------------------------------------------------
> > BEGIN:VCARD
> > FN:Jeffrey L. Oliver
> > N:Oliver;Jeffrey L.
> > ORG:University of Lethbridge
> > ADR:;;4401 University Drive;Lethbridge;Alberta;T1K 3M4
> > EMAIL;INTERNET:oliver @
> > TITLE:System Support Specialist
> > TEL;WORK:(403) 329-5162
> > TEL;FAX:(403) 382-7108
> > X-NAV-HTML:T
> > END:VCARD
> The rule set will start at rule number one and work its way down to the
> last rule or until a rule condition has been satisfied.
John is correct and since FW-1 does that for each and every packet, you
can minimize the time spent finding the corresponding rule by:
1) Start with rules that accept packets, followed by rules that block packets.
This is my preferred logic, since I terminate my policy with a block
all and log rule.
2) Start with rules that handle the most frequent services, followed by rules
that handle the least frequent services.
This has to do with the top-to-bottom sequential search.
3) End with a rule that drops all and logs it.
Sometimes it is more important to know what you are blocking instead
of what you are accepting.
4) Consider unchecking all of the Properties, forcing the policy to handle
everything. This enables you to
b) log everything
Not necessary, but it is an option that you might want to have known about.
/\ Jerald E. Josephs
\\ \ Course Developer - Network Security
\ \\ / Sun Educational Services
/ \/ / /
/ / \//\
\//\ / /
/ / /\ /
/ \\ \ Phone/VM: 408-276-0941
\ \\ FAX: 408-276-1565
\/ E-mail: jerald .