Educause Security Discussion mailing list archives

Preparing for Default Deny Firewall


From: "Cary, Kim" <Kim.Cary () PEPPERDINE EDU>
Date: Tue, 1 Feb 2005 08:04:41 -0800

We will shortly be going to an default-deny firewall (inbound only)
here (8000 students 1000 staff, 7 campuses on a WAN).

For those of you that have such a situation, I would appreciate any
tips you have for:
1. Moving from block known bad to permit known good inbound posture.
2. Procedures you have to processing & approving exceptions for new or
changed services.

For those of you that decided against this type of firewall, I think
our implementation would be informed of some things to look out for by
hearing from you about your issues that prevent you from going to this
position.

We also are in receipt of a recommendation that states our router ACLs
should also be default deny. Any tips/comments on that recommendation
would be welcome as well.

Kim Cary
Infrastructure Security Administrator
Pepperdine University
310 506 6655

**********
Participation and subscription information for this EDUCAUSE Discussion Group discussion list can be found at 
http://www.educause.edu/groups/.

Current thread: