Èçäàòåëüñêèé äîì ÎÎÎ "Ãåéì Ëýíä"ÑÏÅÖÂÛÏÓÑÊ ÆÓÐÍÀËÀ ÕÀÊÅÐ #72, ÍÎßÁÐÜ 2006 ã.

ñîâåðøåííî ñåêðåòíî

ÐÎÌÀÍ ËÓÊÎÂÍÈÊÎÂ (LRB@SANDY.RU)

Ñïåöâûïóñê: Õàêåð, íîìåð #072, ñòð. 072-010-8


11 ÍÀ ÇÀÊËÀÄÊÅ PROTOCOL ÂÛÁÈÐÀÅØÜ ÒÈÏ ÏÐÎÒÎÊÎËÀ TCP Ñ ËÞÁÎÃÎ ÏÎÐÒÀ ÍÀ 139 È ÆÌÅØÜ ÎÊ

12 ÍÀÆÈÌÀÅØÜ ADD...

13  SOURCE ADDRESS ÂÛÁÈÐÀÅØÜ A SPECIFIC IP SUBNET È ÏÈØÅØÜ ÀÄÐÅÑ È ÌÀÑÊÓ ÄËß ÑÅÒÈ «À»,  DESTINATION ADDRESS ÓÊÀÇÛÂÀÅØÜ MY IP ADDRESS. ÎÑÒÀÂËßÅØÜ ÎÏÖÈÞ MIRRORED. ALSO MATCH PACKETS WITH THE EXACT OPPOSITE SOURCE AND DESTINATION ADDRESSES.

14 ÍÀ ÇÀÊËÀÄÊÅ PROTOCOL ÂÛÁÈÐÀÅØÜ ÒÈÏ ÏÐÎÒÎÊÎËÀ TCP Ñ ËÞÁÎÃÎ ÏÎÐÒÀ ÍÀ 445 È ÆÌÅØÜ ÎÊ.

15 ÇÀÊÐÛÂÀÅØÜ IP FILTER LIST, ÍÀÆÈÌÀß CLOSE.

16 ÍÀ ÇÀÊËÀÄÊÅ IP FILTER LIST ÂÛÁÈÐÀÅØÜ ÒÎËÜÊÎ ×ÒÎ ÑÎÇÄÀÍÍÛÉ INBOUND SMB.

17 ÍÀ ÇÀÊËÀÄÊÅ AUTHENTICATION METHOD ÂÛÁÈÐÀÅØÜ ÌÅÒÎÄ ÀÓÒÅÍÒÈÔÈÊÀÖÈÈ (ÅÑËÈ ÊÎÌÏÜÞÒÅÐÛ ÈÇ ÎÄÍÎÃÎ ÄÎÌÅÍÀ, ÅÑÒÅÑÒÂÅÍÍÎ, ÎÑÒÀÂËßÅØÜ KERBEROS, ÅÑËÈ ÅÑÒÜ ÓÄÎÑÒÎÂÅÐßÞÙÈÉ ÖÅÍÒÐ È ÑÎÎÒÂÅÒÑÒÂÓÞÙÈÅ ÑÅÐÒÈÔÈÊÀÒÛ IPSEC, ÂÛÁÈÐÀÅØÜ USE CERTIFICATE,  ÏÐÎÒÈÂÍÎÌ ÑËÓ×ÀÅ ÏÎËÜÇÓÅØÜÑß PRESHARED KEY).

18 ÍÀ ÇÀÊËÀÄÊÅ FILTER ACTION ÂÛÁÈÐÀÅØÜ REQUIRE SECURITY, ÍÀÆÈÌÀÅØÜ EDIT...

19 ÓÁÈÐÀÅØÜ (ÅÑËÈ ÓÑÒÀÍÎÂËÅÍÀ) ÎÏÖÈÞ ACCEPT UNSECURED COMMUNICATION, BUT ALWAYS RESPOND USING IPSEC È ÍÀÆÈÌÀÅØÜ OK, ÄÀËÅÅ CLOSE.

20 Â ÑÏÈÑÊÅ ÏÐÀÂÈË ÍÀÆÈÌÀÅØÜ ADD... È ÂÛÁÈÐÀÅØÜ ALL ICMP TRAFFIC.

21 ÍÀ ÇÀÊËÀÄÊÅ AUTHENTICATION METHOD ÂÛÁÈÐÀÅØÜ ÒÀÊÎÉ ÆÅ ÌÅÒÎÄ, ÊÀÊ Â ÏÓÍÊÒÅ 17.

22 ÍÀ ÇÀÊËÀÄÊÅ FILTER ACTION ÂÛÁÈÐÀÅØÜ PERMIT È ÍÀÆÈÌÀÅØÜ OK.

23 Â ÑÏÈÑÊÅ ÏÐÀÂÈË ÎÏßÒÜ ÍÀÆÈÌÀÅØÜ ADD..., ÂÛÁÈÐÀÅØÜ ALL IP TRAFFIC.

24 ÍÀ ÇÀÊËÀÄÊÅ AUTHENTICATION METHOD ÂÛÁÈÐÀÅØÜ ÒÀÊÎÉ ÆÅ ÌÅÒÎÄ, ÊÀÊ Â ÏÓÍÊÒÅ 17.

25 ÍÀ ÇÀÊËÀÄÊÅ FILTER ACTION ÍÀÆÈÌÀÅØÜ ADD...

26 Â SECURITY METHOD ÂÛÁÈÐÀÅØÜ BLOCK, ÏÅÐÅÕÎÄÈØÜ ÍÀ ÇÀÊËÀÄÊÓ GENERAL È ÏÈØÅØÜ ÒÀÌ BLOCK TRAFFIC, ÍÀÆÈÌÀÅØÜ ÍÀ OK.

27 Â ÎÊÎØÊÅ FILTER ACTION ÂÛÁÈÐÀÅØÜ BLOCK TRAFFIC È CLOSE.

 èòîãå ïîëó÷èëîñü òðè ïðàâèëà. Ïîðÿäîê èõ íå ìåíÿåòñÿ, è ïðèìåíÿþòñÿ îíè ïî ñïåöèôè÷íîñòè. Òî åñòü åñëè ïîéäóò âõîäÿùèå ICMP-ïàêåòû, ñðàáîòàåò ïðàâèëî Allow ICMP traffic è ò.ä.

Çàêðûâàåøü îêíà è íàçíà÷àåøü ñîçäàííóþ ïîëèòèêó. Äëÿ ýòîãî íà èìåíè ïîëèòèêè IPSec for File Server ïðàâûé êëèê, â êîíòåêñòíîì ìåíþ — Assign.

Äëÿ ïðèìåíåíèÿ èçìåíåíèé ïåðåçàïóñêàåøü ñëóæáó IPSec:

ËÈÑÒÈÍÃ

net stop policyagent

net start policyagent

Íàñòðàèâàåøü IPSec-ïîëèòèêó íà êëèåíòñêîì êîìïüþòåðå (ðàñïðîñòðàíèòü ïîëèòèêó íà äðóãèå ìàøèíû ìîæíî ëèáî ÷åðåç ãðóïïîâóþ ïîëèòèêó, åñëè åñòü äîìåí, ëèáî ÷åðåç îñíàñòêó Security Templates è ýêñïîðò ïîëèòèê):

1 ÌÅÍÞ START, ÄÀËÅÅ RUN, ÍÀÁÈÐÀÅØÜ SECPOL.MSC È ÍÀÆÈÌÀÅØÜ ENTER.

2 ÏÐÀÂÛÉ ÊËÈÊ ÍÀ IP SECURITY POLICIES ON LOCAL MACHINE, ÄÀËÅÅ ÊËÈÊ CREATE IP SECURITY POLICY.

3 ÊËÈÊÀÅØÜ NEXT.

4 ÏÈØÅØÜ ÈÌß ÍÎÂÎÉ ÏÎËÈÒÈÊÈ, ÍÀÏÐÈÌÅÐ, «IPSEC FOR FILE SERVER», ÊËÈÊÀÅØÜ NEXT.

5 ÓÁÈÐÀÅØÜ ÎÏÖÈÞ ACTIVATE THE DEFAULT RESPONSE RULE, ÊËÈÊÀÅØÜ NEXT.

6 ÎÑÒÀÂËßÅØÜ ÎÏÖÈÞ EDIT PROPERTIES, ÊËÈÊÀÅØÜ FINISH.

7 ÄÎÁÀÂËßÅØÜ ÏÐÀÂÈËÎ IPSEC, ÊËÈÊÀß ADD...

8 ÄÎÁÀÂËßÅØÜ IP FILTER, ÊËÈÊÀß ADD...

9 ÍÀÇÛÂÀÅØÜ ÔÈËÜÒÐ OUTBOUND SMB È ÍÀÆÈÌÀÅØÜ ADD...

10  SOURCE ADDRESS ÓÊÀÇÛÂÀÅØÜ MY IP ADDRESS,  DESTINATION ADDRESS ÓÊÀÇÛÂÀÅØÜ IP_ÔÀÉË.ÑÅÐÂÅÐÀ. ÎÑÒÀÂËßÅØÜ ÎÏÖÈÞ MIRRORED. ALSO MATCH PACKETS WITH THE EXACT OPPOSITE SOURCE AND DESTINATION ADDRESSES.

11 ÍÀ ÇÀÊËÀÄÊÅ PROTOCOL ÂÛÁÈÐÀÅØÜ ÒÈÏ ÏÐÎÒÎÊÎËÀ TCP Ñ ËÞÁÎÃÎ ÏÎÐÒÀ ÍÀ 139 È ÆÌÅØÜ ÎÊ.

Íàçàä íà ñòð. 072-010-7  Ñîäåðæàíèå  Âïåðåä íà ñòð. 072-010-9