{"id":3605,"date":"2020-01-23T12:31:44","date_gmt":"2020-01-23T12:31:44","guid":{"rendered":"https:\/\/nissa.gov.ly\/%d8%b3%d9%8a%d8%a7%d8%b3%d8%a9-%d8%ad%d9%85%d8%a7%d9%8a%d8%a9-%d8%a7%d9%84%d8%b4%d8%a8%d9%83%d8%a7%d8%aa\/"},"modified":"2020-04-19T20:40:17","modified_gmt":"2020-04-19T20:40:17","slug":"network-security-policies","status":"publish","type":"page","link":"https:\/\/nissa.gov.ly\/en\/main-services\/network-security-policies\/","title":{"rendered":"Network Security Policy"},"content":{"rendered":"<div>\n<p>        <img decoding=\"async\" src=\"wp-content\/uploads\/download-pdf.svg\" alt=\"\"><\/p>\n<h6>You can National Information Security &#038; Safety Authority policies as pdf by clicking on this link<\/h6>\n<p><a href=\"wp-content\/uploads\/NISSA_Policy_Manual_v1.0-1.pdf\">download<span style=\"padding-right:10px;\" uk-icon=\"arrow-down\"><\/span><\/a><\/p>\n<\/div>\n<h3><b>Router and Switch Security Policy<\/b><\/h3>\n<ul>\n<li>\n<h4>Introduction<\/h4>\n<div>\n<p><span style=\"font-weight: 400;\">Routers and smart switches provide important security functions within a network. Configured correctly, they are one of several hardware and software devices available that help manage and protect a private network from a public one. The Router and Switch Security Policy defines configuration requirements to meet security standards, change management requirements, and operational requirements.<\/span><\/p>\n<\/div>\n<\/li>\n<li>\n<h4>Purpose<\/h4>\n<div>\n<p><span style=\"font-weight: 400;\">This document designed to protect the equipment and data of the <\/span><b>(organization)<\/b><span style=\"font-weight: 400;\"> and its business partners or any data the <\/span><b>(organization)<\/b><span style=\"font-weight: 400;\"> is in custody of by defining the minimum configuration standards for all routers and switches connecting to the organizational network.<\/span><\/p>\n<\/div>\n<\/li>\n<li>\n<h4>Scope<\/h4>\n<div>\n<p><span style=\"font-weight: 400;\">All employees, contractors, consultants, temporary and other workers who use network devices such as Router and\/or switch must adhere to this policy. All routers and switches connected to networks are affected.<\/span><\/p>\n<\/div>\n<\/li>\n<li>\n<h4>Policy<\/h4>\n<div>\n<p class=\"p1\"><span class=\"s1\"><span style=\"font-weight: 400;\">Every router\/switch must meet the following configuration standards<\/span>:\u00a0<\/span><\/p>\n<ol class=\"ol1\">\n<li style=\"font-weight: 400;\"><span style=\"font-weight: 400;\">No local user accounts are configured on the router or switch. Routers and switches must use a dedicated AAA server (e.g. TACACS+) for all user authentication.<\/span><\/li>\n<li style=\"font-weight: 400;\"><span style=\"font-weight: 400;\">The enable secret must be used instead of enable password.<\/span><\/li>\n<li style=\"font-weight: 400;\"><span style=\"font-weight: 400;\">The enable secret on the router or switch must be kept in a secure encrypted form.\u00a0<\/span><\/li>\n<li style=\"font-weight: 400;\"><span style=\"font-weight: 400;\">The following services or features must be disabled: <\/span><\/li>\n<\/ol>\n<ul class=\"ul1\">\n<li style=\"font-weight: 400;\"><span style=\"font-weight: 400;\">IP directed broadcasts (Enable IP directed broadcast when you want to perform remote management or administration services such as backups on hosts in a subnet that does not have a direct connection to the Internet).<\/span><\/li>\n<li style=\"font-weight: 400;\"><span style=\"font-weight: 400;\">Incoming packets at the router\/switch sourced with invalid addresses such as RFC1918 addresses.<\/span><\/li>\n<li style=\"font-weight: 400;\"><span style=\"font-weight: 400;\">TCP small services\u00a0<\/span><\/li>\n<li style=\"font-weight: 400;\"><span style=\"font-weight: 400;\">UDP small services\u00a0<\/span><\/li>\n<li style=\"font-weight: 400;\"><span style=\"font-weight: 400;\">All web services running on router<\/span><\/li>\n<li style=\"font-weight: 400;\"><span style=\"font-weight: 400;\">Auto-configuration.<\/span><\/li>\n<li style=\"font-weight: 400;\"><span style=\"font-weight: 400;\">Layer 2 device discovery protocol (e.g. CDP and LLDP) and other discovery protocols.<\/span><\/li>\n<\/ul>\n<p>5. <span style=\"font-weight: 400;\">Routers and switches and\/or interfaces should disallow the following: <\/span><span class=\"s1\"><br \/><\/span><\/p>\n<ul class=\"ul1\">\n<li style=\"font-weight: 400;\"><span style=\"font-weight: 400;\">Proxy-ARP.<\/span><\/li>\n<li style=\"font-weight: 400;\"><span style=\"font-weight: 400;\">ICMP unreachable messages.\u00a0<\/span><\/li>\n<li style=\"font-weight: 400;\"><span style=\"font-weight: 400;\">Fast switching and autonomous switching.\u00a0<\/span><\/li>\n<li style=\"font-weight: 400;\"><span style=\"font-weight: 400;\">Multicast route caching.<\/span><\/li>\n<li style=\"font-weight: 400;\"><span style=\"font-weight: 400;\">Maintenance Operation Protocol (MOP).<\/span><\/li>\n<\/ul>\n<p>6. <span style=\"font-weight: 400;\">The following services must be configured:<\/span><span class=\"s1\"><br \/><\/span><\/p>\n<ul class=\"ul1\">\n<li style=\"font-weight: 400;\"><span style=\"font-weight: 400;\">Password-encryption<\/span><\/li>\n<li style=\"font-weight: 400;\"><span style=\"font-weight: 400;\">Time syncing (NTP). All network clocks should be synced to a common time source.<\/span><\/li>\n<\/ul>\n<p><span style=\"font-weight: 400;\">7. All routing updates shall be done using secure routing updates.<\/span><\/p>\n<p><span style=\"font-weight: 400;\">8. Use (<\/span><b>organization<\/b><span style=\"font-weight: 400;\">) standardized SNMP community strings.\u00a0 Default strings, such as public or private must be removed.\u00a0 SNMP must be configured to use the most secure version of the protocol allowed for by the combination of the device and management systems.<\/span><\/p>\n<p><span style=\"font-weight: 400;\">9. Access control lists must be used to limit the source and type of traffic that can terminate on the device itself.<\/span><\/p>\n<p><span style=\"font-weight: 400;\">10. Each router must have a Login banners that useful to inform potential users that use of the login is only for authorized users. the following statement presented for all forms of login whether remote or local:\u00a0<\/span><\/p>\n<p><span style=\"font-weight: 400;\">&#8220;UNAUTHORIZED ACCESS TO THIS NETWORK DEVICE IS PROHIBITED.<\/span><\/p>\n<p><span style=\"font-weight: 400;\">You must have explicit permission to access or configure this device. All activities performed on this device may be logged, and violations of this policy may result in disciplinary action in accordance with regulation in force. There is no right to privacy on this device. Use of this system shall constitute consent to monitoring.&#8221;<\/span><\/p>\n<p>\u00a0<\/p>\n<p><span style=\"font-weight: 400;\">11. Telnet may never be used across any network to manage a router, unless there is a secure tunnel protecting the entire communication path. SSH version 2 is the preferred management protocol.<\/span><\/p>\n<p><span style=\"font-weight: 400;\">12. Routers and switches should be placed in a location where physical access is limited to authorized persons only.<\/span><\/p>\n<p><span style=\"font-weight: 400;\">13. The switch should disable a port or group of ports if new or unregistered MAC addresses appear on a port if the feature is available.<\/span><\/p>\n<p><span style=\"font-weight: 400;\">14. The\u00a0 switch\u00a0 should generate\u00a0 an SNMP trap if the\u00a0 link drops and is re-established\u00a0 if the feature is available<\/span><\/p>\n<p><span style=\"font-weight: 400;\">15. Dynamic routing protocols must use authentication in routing updates sent to neighbors.\u00a0 (<\/span><b><i>Password hashing for the authentication string must be enabled when supported<\/i><\/b><span style=\"font-weight: 400;\">).<\/span><\/p>\n<p><span style=\"font-weight: 400;\">16. The (<\/span><b>organization<\/b><span style=\"font-weight: 400;\">) router configuration standard will define the category of sensitive routing and switching devices, and require additional services or configuration on sensitive devices including:<\/span><\/p>\n<ul>\n<li style=\"font-weight: 400;\"><span style=\"font-weight: 400;\">IP access list accounting<\/span><\/li>\n<li style=\"font-weight: 400;\"><span style=\"font-weight: 400;\">Device logging<\/span><\/li>\n<li style=\"font-weight: 400;\"><span style=\"font-weight: 400;\">Incoming packets at the router sourced with invalid addresses, such as RFC1918 addresses, or those that could be used to spoof network traffic shall be dropped.<\/span><\/li>\n<\/ul>\n<p><span style=\"font-weight: 400;\">17. Network configurations and changes must be documented regularly to understand its structure. Network documentation should include:\u00a0<\/span><\/p>\n<ul>\n<li style=\"font-weight: 400;\"><span style=\"font-weight: 400;\">\u00a0Network diagram\u00a0<\/span><\/li>\n<li style=\"font-weight: 400;\"><span style=\"font-weight: 400;\">\u00a0System configurations\u00a0<\/span><\/li>\n<li style=\"font-weight: 400;\"><span style=\"font-weight: 400;\">\u00a0Firewall rule set\u00a0<\/span><\/li>\n<li style=\"font-weight: 400;\"><span style=\"font-weight: 400;\">\u00a0IP Addresses<\/span><\/li>\n<li style=\"font-weight: 400;\"><span style=\"font-weight: 400;\">Access Control Lists<\/span><\/li>\n<\/ul>\n<ul class=\"ul1\">\n<li class=\"li2\" style=\"list-style-type: none;\">\u00a0<\/li>\n<\/ul>\n<\/div>\n<\/li>\n<\/ul>\n<h2><b>Wireless Communication Policy<\/b><\/h2>\n<ul>\n<li>\n<h3>Introduction<\/h3>\n<div>\n<p><span style=\"font-weight: 400;\">With the mass explosion of Smart Phones and Tablets, pervasive wireless connectivity is almost a given at any organization. Insecure wireless configuration can provide an easy open door for malicious threat actors.\u00a0<\/span><\/p>\n<p><span style=\"font-weight: 400;\">A Wireless Communication Policy is necessary for computer security since there is demand for wireless equipment in every (<\/span><b>organization<\/b><span style=\"font-weight: 400;\">) today. The Wireless Communication Policy may specify that no wireless equipment should be used but this would not be very good since that may cause some departments or individuals to violate the policy. It is best to set conditions and specify equipment that is approved for wireless use in order to minimize security risk associated with wireless.<\/span><\/p>\n<\/div>\n<\/li>\n<li>\n<h3>Purpose<\/h3>\n<div>\n<p><span style=\"font-weight: 400;\">The purpose of this policy is to secure and protect the information assets owned by <\/span><b>(Organization)<\/b><span style=\"font-weight: 400;\">. <\/span><b>(Organization)<\/b><span style=\"font-weight: 400;\"> grants access to these resources as a privilege and must manage them responsibly to maintain the confidentiality, integrity, and availability of all information assets.<\/span><\/p>\n<p><span style=\"font-weight: 400;\">This policy specifies the conditions that wireless infrastructure devices must satisfy to connect to <\/span><b>(Organization)<\/b><span style=\"font-weight: 400;\"> network. Only <\/span><b>those<\/b><span style=\"font-weight: 400;\"> wireless infrastructure devices that meet the standards <\/span><b>specified in<\/b><span style=\"font-weight: 400;\">\u00a0this policy, or that granted an exception by the Information Security Department are approved for connectivity to a <\/span><b>(Organization)<\/b><span style=\"font-weight: 400;\"> network.<\/span><\/p>\n<\/div>\n<\/li>\n<li>\n<h3>Scope<\/h3>\n<div>\n<p><span style=\"font-weight: 400;\">This policy applies to all wireless infrastructure devices that connect to a <\/span><b>(Organization)<\/b><span style=\"font-weight: 400;\"> network or reside on a <\/span><b>(Organization)<\/b><span style=\"font-weight: 400;\"> site that provide wireless connectivity to endpoint devices including, but not limited to, laptops, desktops, cellular phones, and tablets. This includes any form of wireless communication device capable of transmitting packet data .Therefore, all employees, contractors, consultants, temporary and other workers at <\/span><b>(Organization)<\/b><span style=\"font-weight: 400;\">, including all personnel affiliated with third parties that maintain a wireless infrastructure device on behalf of <\/span><b>(Organization)<\/b><span style=\"font-weight: 400;\"> must adhere to this policy.<\/span><\/p>\n<\/div>\n<\/li>\n<li>\n<h3>Policy<\/h3>\n<div>\n<p><span style=\"font-weight: 400;\">All wireless infrastructure devices that reside at a <\/span><b>(Organization)<\/b><span style=\"font-weight: 400;\"> site and connect to a (Organization) network, or provide access to information classified as <\/span><b>(Organization)<\/b><span style=\"font-weight: 400;\"> Confidential, or above must:\u00a0<\/span><\/p>\n<ul>\n<li style=\"font-weight: 400;\"><span style=\"font-weight: 400;\">Abide by the standards specified in the Wireless Communication Standard.\u00a0<\/span><\/li>\n<li style=\"font-weight: 400;\"><span style=\"font-weight: 400;\">Use <\/span><b>(Organization)<\/b><span style=\"font-weight: 400;\"> approved authentication protocols and infrastructure.<\/span><\/li>\n<li style=\"font-weight: 400;\"><span style=\"font-weight: 400;\">Use <\/span><b>(Organization)<\/b><span style=\"font-weight: 400;\"> approved encryption protocols.<\/span><\/li>\n<li style=\"font-weight: 400;\"><span style=\"font-weight: 400;\">Maintain a hardware address (MAC address) that can be registered and tracked.\u00a0<\/span><\/li>\n<\/ul>\n<p><span style=\"font-weight: 400;\">To stop the possible abuse of wireless network:<\/span><\/p>\n<ul>\n<li style=\"font-weight: 400;\"><span style=\"font-weight: 400;\">There should be proper user authentication ensured along with the appropriate replacement of WEP and anomaly tracking mechanism on wireless LAN.\u00a0<\/span><\/li>\n<li style=\"font-weight: 400;\"><span style=\"font-weight: 400;\">At the same time, there is the following list of suspicious events on wireless LAN which should always consider for intrusion detection as;<\/span><\/li>\n<\/ul>\n<ul>\n<li style=\"font-weight: 400;\"><span style=\"font-weight: 400;\">Beacon frames from unsolicited access point<\/span><\/li>\n<li style=\"font-weight: 400;\"><span style=\"font-weight: 400;\">Flood of unauthenticated frames (MITM attack)<\/span><\/li>\n<li style=\"font-weight: 400;\"><span style=\"font-weight: 400;\">Frames with duplicated MAC address.<\/span><\/li>\n<li style=\"font-weight: 400;\"><span style=\"font-weight: 400;\">Randomly changing MAC address<\/span><\/li>\n<\/ul>\n<p><span style=\"font-weight: 400;\">Wireless encryption protocols\u00a0<\/span><\/p>\n<ul>\n<li style=\"font-weight: 400;\"><span style=\"font-weight: 400;\">WAP2 (Wi-Fi Protected Access version 2) is preferred as a wireless encryption protocol instead of WEP (Wired Equivalent Privacy) and WAP (Wi-Fi Protected Access\u00a0), because WAP2 It offered a much stronger security algorithm and advanced level encryption with message authenticity and integrity validation while WEP\u00a0and\u00a0WPA\u00a0protocols are considered vulnerable.<\/span><\/li>\n<\/ul>\n<p><span style=\"font-weight: 400;\">Network configurations and changes must be documented regularly to understand its structure. Network documentation should include:\u00a0<\/span><\/p>\n<ul>\n<li style=\"font-weight: 400;\"><span style=\"font-weight: 400;\">Network diagram\u00a0<\/span><\/li>\n<li style=\"font-weight: 400;\"><span style=\"font-weight: 400;\">System configurations\u00a0<\/span><\/li>\n<li style=\"font-weight: 400;\"><span style=\"font-weight: 400;\">\u00a0Firewall rule set\u00a0<\/span><\/li>\n<li style=\"font-weight: 400;\"><span style=\"font-weight: 400;\">\u00a0IP Addresses<\/span><\/li>\n<li style=\"font-weight: 400;\"><span style=\"font-weight: 400;\">Access Control Lists<\/span><\/li>\n<\/ul>\n<\/div>\n<\/li>\n<\/ul>\n<h2><b>Virtual Private Network (VPN) Policy<\/b><\/h2>\n<ul>\n<li>\n<h3>Introduction<\/h3>\n<div>\n<p><span style=\"font-weight: 400;\">A Virtual Private Network (VPN) is a secured private network connection that provide a convenient way to access internal network resources remotely over the public network (Internet). VPN offers secure access by providing a means to protect data while it travels over an untrusted network. <\/span><\/p>\n<\/div>\n<\/li>\n<li>\n<h3>Purpose<\/h3>\n<div>\n<p><span style=\"font-weight: 400;\">The purpose of this policy is to provide guidelines for Remote Access IPsec or L2TP Virtual Private Network (VPN) connections to the <\/span><b>(Organization)<\/b><span style=\"font-weight: 400;\"> corporate network.\u00a0 <\/span><\/p>\n<\/div>\n<\/li>\n<li>\n<h3>Scope<\/h3>\n<div>\n<p><span style=\"font-weight: 400;\">This policy applies to all <\/span><b>(Organization)<\/b><span style=\"font-weight: 400;\"> employees, contractors, consultants, temporaries, and other workers including all personnel affiliated with third parties utilizing VPNs to access the <\/span><b>(Organization)<\/b><span style=\"font-weight: 400;\"> network. This policy applies to implementations of VPN that are directed through an IPsec Concentrator. <\/span><\/p>\n<\/div>\n<\/li>\n<li>\n<h3>Policy<\/h3>\n<div>\n<ol>\n<li><span style=\"font-weight: 400;\">It is the responsibility of employees with VPN privileges to ensure that unauthorized users are not allowed access to <\/span><b>(Organization)<\/b><span style=\"font-weight: 400;\"> internal networks through their VPN connection.\u00a0<\/span><\/li>\n<li><span style=\"font-weight: 400;\">VPN use is to be controlled using either a one-time password authentication such as a token device or a public\/private key system with a strong passphrase.\u00a0<\/span><\/li>\n<li><span style=\"font-weight: 400;\">When actively connected to the corporate network, VPNs will force all traffic to and from the PC used by the remote user over the VPN tunnel: all other traffic will be dropped.\u00a0<\/span><\/li>\n<li><span style=\"font-weight: 400;\">Dual (split) tunneling is NOT permitted; only one network connection is allowed.\u00a0 [<\/span><i><span style=\"font-weight: 400;\">Dual (split) tunneling allows two simultaneous, active connections to a secure network (via VPN) and a non-secure network, without having to disconnect the VPN connection. This security vulnerability allows a direct connection from the non-secured Internet to the VPN secured network.<\/span><\/i><span style=\"font-weight: 400;\">]<\/span><\/li>\n<li><span style=\"font-weight: 400;\">VPN gateways will be set up and managed by <\/span><b>(Organization)<\/b><span style=\"font-weight: 400;\"> network operational groups.\u00a0<\/span><\/li>\n<li><span style=\"font-weight: 400;\">All computers connected to <\/span><b>(Organization)<\/b><span style=\"font-weight: 400;\"> internal networks via VPN or any other technology must use the most up-to-date anti-virus software that is the corporate standard (provide URL to this software); this includes <\/span><span style=\"font-weight: 400;\">personal computers.\u00a0<\/span><\/li>\n<li><span style=\"font-weight: 400;\">VPN users will be automatically disconnected from <\/span><b>(Organization)<\/b><span style=\"font-weight: 400;\">&#8216;s network after thirty minutes of inactivity. The user must then logon again to reconnect to the network. <\/span><i><span>(Pings or other artificial network processes are not to be used to keep the connection open.)\u00a0<\/span><\/i><\/li>\n<li><span style=\"font-weight: 400;\">The VPN concentrator must be limited to an absolute connection time of 24 hours.\u00a0<\/span><\/li>\n<li><span style=\"font-weight: 400;\">Users of computers that are not <\/span><b>(Organization)<\/b><span style=\"font-weight: 400;\">-owned equipment must configure the equipment to comply with <\/span><b>(Organization)<\/b><span style=\"font-weight: 400;\">&#8216;s VPN and Network policies.\u00a0<\/span><\/li>\n<li><span style=\"font-weight: 400;\">By using VPN technology with personal equipment, users must understand that their machines are a de facto extension of <\/span><b>(Organization)<\/b><span style=\"font-weight: 400;\">&#8216;s network, and as such are subject to the same rules and regulations that apply to <\/span><b>(Organization)<\/b><span style=\"font-weight: 400;\">-owned equipment.<\/span><\/li>\n<li><span style=\"font-weight: 400;\">Network configurations and changes must be documented regularly to understand its structure. Network documentation should include:\u00a0<\/span><\/li>\n<\/ol>\n<ul>\n<li style=\"list-style-type: none;\">\n<ul>\n<li><span style=\"font-weight: 400;\">\u00a0Network diagram\u00a0<\/span><\/li>\n<li><span style=\"font-weight: 400;\">\u00a0System configurations\u00a0<\/span><\/li>\n<li><span style=\"font-weight: 400;\">\u00a0Firewall rule set\u00a0<\/span><\/li>\n<li><span style=\"font-weight: 400;\">\u00a0IP Addresses<\/span><\/li>\n<li><span style=\"font-weight: 400;\">Access Control Lists<\/span><\/li>\n<\/ul>\n<\/li>\n<\/ul>\n<\/div>\n<\/li>\n<\/ul>\n<h2><b>Firewall Policy<\/b><\/h2>\n<ul>\n<li>\n<h3>Introduction<\/h3>\n<div>\n<p><span style=\"font-weight: 400;\">When a user connects to an insecure, open network, such as the Internet, he opens a large doorway for potential attacks. One of the best ways to defense against exploitation from the insecure network is to employ firewalls at the connection point end, as it is a necessity to safeguard the<\/span> <b>(Organization)<\/b><span style=\"font-weight: 400;\">\u2019s private networks and communication facilities. <\/span><\/p>\n<\/div>\n<\/li>\n<li>\n<h3>Purpose<\/h3>\n<div>\n<p><span style=\"font-weight: 400;\">Firewalls are defined as security systems that control and restrict network connectivity and network services. Firewalls establish a control point where access controls may be enforced. This document seeks to assist <\/span><b>(Organization)<\/b><span style=\"font-weight: 400;\"> in understanding the capabilities of firewall technologies and firewall policies.<\/span><\/p>\n<\/div>\n<\/li>\n<li>\n<h3>Scope<\/h3>\n<div>\n<p><span style=\"font-weight: 400;\">This policy defines the essential rules regarding the management and maintenance of firewalls, and it applies to all firewalls owned, rented, leased, or otherwise controlled by <\/span><b>(Organization)<\/b><span style=\"font-weight: 400;\">.<\/span><\/p>\n<\/div>\n<\/li>\n<li>\n<div>\n<ol>\n<li style=\"font-weight: 400;\"><span style=\"font-weight: 400;\">Review the rulesets to ensure that they follow the order as follows:<\/span><\/li>\n<\/ol>\n<ul>\n<li style=\"list-style-type: none;\">\n<ul>\n<li style=\"font-weight: 400;\"><span style=\"font-weight: 400;\">anti-spoofing filters (blocked private addresses, internal addresses appearing from the outside)<\/span><\/li>\n<li style=\"font-weight: 400;\"><span style=\"font-weight: 400;\">User permit rules (e.g. allow HTTP to public webserver)<\/span><\/li>\n<li style=\"font-weight: 400;\"><span style=\"font-weight: 400;\">Management permit rules (e.g. SNMP traps to network management server)<\/span><\/li>\n<li style=\"font-weight: 400;\"><span style=\"font-weight: 400;\">Deny and Alert (alert systems administrator about traffic that is suspicious)<\/span><\/li>\n<li style=\"font-weight: 400;\"><span style=\"font-weight: 400;\">Deny and log (log remaining traffic for analysis)<\/span><\/li>\n<\/ul>\n<\/li>\n<\/ul>\n<ol>\n<li style=\"font-weight: 400;\"><span style=\"font-weight: 400;\">\u00a0Application based firewall:<\/span><\/li>\n<\/ol>\n<ul>\n<li style=\"list-style-type: none;\">\n<ul>\n<li><span style=\"font-weight: 400;\">In the case of dedicated server access, an <\/span><b>application proxy firewall<\/b><span style=\"font-weight: 400;\"> must be placed between the remote user and dedicated server to hide the identity of the server.<\/span><\/li>\n<li><span style=\"font-weight: 400;\">Ensure that the administrators monitor any attempts to violate the security policy using the audit logs generated by the application level firewall.<\/span><\/li>\n<li><span style=\"font-weight: 400;\">Ensure that there is a process to update the application level firewall\u2019s vulnerabilities checked to the most current vulnerabilities.<\/span><\/li>\n<li><span style=\"font-weight: 400;\">Ensure that there is a process to update the software with the latest attack signatures.<\/span><\/li>\n<li><span style=\"font-weight: 400;\">In the event of the signatures being downloaded from the vendors\u2019 site, ensure that it is a trusted site.<\/span><\/li>\n<li><span style=\"font-weight: 400;\">In the event of the signature being e-mailed to the systems administrator, ensure that digital signatures are used to verify the vendor and that the information transmitted has not been modified en-route.<\/span><\/li>\n<li><span style=\"font-weight: 400;\">The following commands should be blocked for SMTP at the application level firewall:<\/span>\n<ul>\n<li style=\"font-weight: 400;\"><span style=\"font-weight: 400;\">EXPN (expand)<\/span><\/li>\n<li style=\"font-weight: 400;\"><span style=\"font-weight: 400;\">VRFY (verify)<\/span><\/li>\n<li style=\"font-weight: 400;\"><span style=\"font-weight: 400;\">DEBUG<\/span><\/li>\n<li style=\"font-weight: 400;\"><span style=\"font-weight: 400;\">WIZARD<\/span><\/li>\n<\/ul>\n<\/li>\n<\/ul>\n<\/li>\n<\/ul>\n<ul>\n<li style=\"list-style-type: none;\">\n<ul>\n<li style=\"font-weight: 400;\"><span style=\"font-weight: 400;\">The following command should be blocked for FTP:<\/span><\/li>\n<\/ul>\n<\/li>\n<\/ul>\n<ul>\n<li style=\"list-style-type: none;\">\n<ul>\n<li style=\"list-style-type: none;\">\n<ul>\n<li style=\"font-weight: 400;\"><span style=\"font-weight: 400;\">PUT<\/span><\/li>\n<\/ul>\n<\/li>\n<\/ul>\n<\/li>\n<\/ul>\n<ul>\n<li style=\"list-style-type: none;\">\n<ul>\n<li style=\"font-weight: 400;\"><span style=\"font-weight: 400;\">Review the denied URL\u2019s and ensure that they are appropriate for e.g. any URL\u2019s to hacker sites should be blocked.\u00a0<\/span><\/li>\n<li style=\"font-weight: 400;\"><span style=\"font-weight: 400;\">Ensure that only authorized users are authenticated by the application level firewall.<\/span><\/li>\n<\/ul>\n<\/li>\n<\/ul>\n<ol>\n<li style=\"font-weight: 400;\"><span style=\"font-weight: 400;\">Stateful inspection<\/span><\/li>\n<\/ol>\n<ul>\n<li style=\"list-style-type: none;\">\n<ul>\n<li style=\"font-weight: 400;\"><span style=\"font-weight: 400;\">Review the state tables to ensure that appropriate rules are set up in terms of source and destination IP\u2019s, source and destination ports and timeouts.<\/span><\/li>\n<li style=\"font-weight: 400;\"><span style=\"font-weight: 400;\">Ensure that the timeouts are appropriate so as not to give the hacker too much time to launch a successful attack.<\/span><\/li>\n<\/ul>\n<\/li>\n<\/ul>\n<p><span style=\"font-weight: 400;\">For URL\u2019s<\/span><\/p>\n<ul>\n<li style=\"list-style-type: none;\">\n<ul>\n<li style=\"font-weight: 400;\"><span style=\"font-weight: 400;\">If a URL filtering server is used, ensure that it is appropriately defined in the firewall software. (If the filtering server is external to the (<\/span><b>Organization<\/b><span style=\"font-weight: 400;\">) ensure that it is a trusted source).<\/span><\/li>\n<li style=\"font-weight: 400;\"><span style=\"font-weight: 400;\">If filtering on MAC addresses is allowed, review the filters to ensure that it is restricted to the appropriate MAC\u2019s at (<\/span><b>Organization<\/b><span style=\"font-weight: 400;\">).<\/span><\/li>\n<\/ul>\n<\/li>\n<\/ul>\n<ol>\n<li style=\"font-weight: 400;\"><span style=\"font-weight: 400;\">Logging<\/span><\/li>\n<\/ol>\n<ul>\n<li style=\"list-style-type: none;\">\n<ul>\n<li style=\"font-weight: 400;\"><span style=\"font-weight: 400;\">Ensure that logging is enabled and that the logs are reviewed to identify any potential patterns that could indicate an attack.<\/span><\/li>\n<li style=\"font-weight: 400;\"><span style=\"font-weight: 400;\">Network Firewall administration logs (administrative activities) and event logs (traffic activity) should:<\/span><\/li>\n<\/ul>\n<\/li>\n<\/ul>\n<ul>\n<li style=\"list-style-type: none;\">\n<ul>\n<li style=\"font-weight: 400;\"><span style=\"font-weight: 400;\">Be written to alternate storage (not on the same device)\u00a0<\/span><\/li>\n<li style=\"font-weight: 400;\"><span style=\"font-weight: 400;\">Be reviewed at least daily, with logs retained for ninety (90) days.\u00a0<\/span><\/li>\n<\/ul>\n<\/li>\n<\/ul>\n<ol>\n<li style=\"font-weight: 400;\"><span style=\"font-weight: 400;\">Patches and updates<\/span><\/li>\n<\/ol>\n<ul>\n<li style=\"list-style-type: none;\">\n<ul>\n<li style=\"font-weight: 400;\"><span style=\"font-weight: 400;\">Ensure that the latest patches and updates relating to your firewall product is tested and installed.<\/span><\/li>\n<li style=\"font-weight: 400;\"><span style=\"font-weight: 400;\">If patches and updates are automatically downloaded from the vendors\u2019 websites, ensure that the update is received from a trusted site.<\/span><\/li>\n<li style=\"font-weight: 400;\"><span style=\"font-weight: 400;\">In the event that patches and updates are e-mailed to the systems administrator ensure that digital signatures are used to verify the vendor and ensure that the information has not been modified en-route.<\/span><\/li>\n<\/ul>\n<\/li>\n<\/ul>\n<ol>\n<li style=\"font-weight: 400;\"><span style=\"font-weight: 400;\">Vulnerability assessments\/ Testing<\/span><\/li>\n<\/ol>\n<ul>\n<li style=\"list-style-type: none;\">\n<ul>\n<li style=\"font-weight: 400;\"><span style=\"font-weight: 400;\">Ascertain if there is a procedure to test for open ports using (NMAP) and whether unnecessary ports are closed.<\/span><\/li>\n<li style=\"font-weight: 400;\"><span style=\"font-weight: 400;\">Ensure that there is a procedure to test the rulesets when established or changed so as not to create a denial of service on the (<\/span><b>organization<\/b><span style=\"font-weight: 400;\">) or allow any weaknesses to continue undetected.<\/span><\/li>\n<\/ul>\n<\/li>\n<\/ul>\n<ol>\n<li style=\"list-style-type: none;\">\n<ol>\n<li style=\"font-weight: 400;\"><span style=\"font-weight: 400;\">Compliance with security policy<\/span><\/li>\n<\/ol>\n<\/li>\n<\/ol>\n<ul>\n<li style=\"list-style-type: none;\">\n<ul>\n<li style=\"font-weight: 400;\"><span style=\"font-weight: 400;\">Ensure that the ruleset complies with the (<\/span><b>organization<\/b><span style=\"font-weight: 400;\">) security policy.<\/span><\/li>\n<li><span style=\"font-weight: 400;\">\u00a0Ensure that the following spoofed, private (RFC 1918) and illegal addresses are blocked:<\/span><\/li>\n<\/ul>\n<\/li>\n<li><b>Private (RFC 1918) addresses<\/b><\/li>\n<\/ul>\n<p style=\"padding-left: 40px;\"><span style=\"font-weight: 400;\">10.0.0.0 \u2013 10.255.255.255<\/span><\/p>\n<p style=\"padding-left: 40px;\"><span style=\"font-weight: 400;\">172.16.0.0 \u2013 172.31.255.255<\/span><\/p>\n<p style=\"padding-left: 40px;\"><span style=\"font-weight: 400;\">192.168.0.0 &#8211; 192.168.255.255<\/span><\/p>\n<ul>\n<li><b>Reserved addresses<\/b><\/li>\n<\/ul>\n<p style=\"padding-left: 40px;\"><span style=\"font-weight: 400;\">240.0.0.0<\/span><\/p>\n<ul>\n<li><b>Illegal addresses<\/b>\n<ul>\n<li style=\"list-style-type: none;\">\n<ul>\n<li><b><\/b>\n<p><span style=\"font-weight: 400;\">0.0.0.0<\/span><\/p>\n<ul>\n<li style=\"font-weight: 400;\"><span style=\"font-weight: 400;\">UDP echo<\/span><\/li>\n<li style=\"font-weight: 400;\"><span style=\"font-weight: 400;\">ICMP broadcast (RFC 2644)<\/span><\/li>\n<\/ul>\n<\/li>\n<\/ul>\n<\/li>\n<\/ul>\n<\/li>\n<\/ul>\n<ol>\n<li style=\"font-weight: 400;\"><span style=\"font-weight: 400;\">Remote access<\/span><\/li>\n<\/ol>\n<ul>\n<li style=\"font-weight: 400;\"><span style=\"font-weight: 400;\">If remote access is to be used, ensure that the SSH protocol (port 22) is used instead of Telnet.<\/span><\/li>\n<\/ul>\n<ol>\n<li style=\"font-weight: 400;\"><span style=\"font-weight: 400;\">\u00a0File Transfers<\/span><\/li>\n<\/ol>\n<ul>\n<li style=\"font-weight: 400;\"><span style=\"font-weight: 400;\">If FTP is a requirement, ensure that the server, which supports FTP, is placed in a different subnet than the internal protected network.<\/span><\/li>\n<\/ul>\n<ol>\n<li style=\"font-weight: 400;\"><span style=\"font-weight: 400;\">Mail Traffic<\/span><\/li>\n<\/ol>\n<ul>\n<li style=\"font-weight: 400;\"><span style=\"font-weight: 400;\">Ascertain which protocol is used for mail and ensure that there is a rule to block incoming mail traffic except to internal mail.<\/span><\/li>\n<\/ul>\n<ol>\n<li style=\"font-weight: 400;\"><span style=\"font-weight: 400;\">Block Unwanted ICMP Traffic (ICMP 8, 11, 3)<\/span><\/li>\n<\/ol>\n<ul>\n<li style=\"font-weight: 400;\"><span style=\"font-weight: 400;\">Ensure that there is a rule blocking ICMP echo requests and replies.<\/span><\/li>\n<li style=\"font-weight: 400;\"><span style=\"font-weight: 400;\">Ensure that there is a rule blocking outgoing time exceeded and unreachable messages.<\/span><\/li>\n<\/ul>\n<ol>\n<li style=\"font-weight: 400;\"><span style=\"font-weight: 400;\">Critical servers<\/span><\/li>\n<\/ol>\n<ul>\n<li style=\"font-weight: 400;\"><span style=\"font-weight: 400;\">Ensure that there is a deny rule for traffic destined to critical internal addresses from external sources. This rule is based on the organizational requirements, since some <\/span><b>(organizations)<\/b><span style=\"font-weight: 400;\"> may allow traffic via a web application to be routed via a DMZ.<\/span><\/li>\n<\/ul>\n<ol>\n<li style=\"font-weight: 400;\"><span style=\"font-weight: 400;\">Personal firewalls<\/span><\/li>\n<\/ol>\n<ul>\n<li style=\"font-weight: 400;\"><span style=\"font-weight: 400;\">Ensure that laptop users are given appropriate training regarding the threats, types of elements blocked by the firewall and guidelines for operation of the personal firewall. This element is essential, since often times personal firewalls rely on user prompt to respond to attacks e.g. whether to accept\/deny a request from a specific address.<\/span><\/li>\n<li style=\"font-weight: 400;\"><span style=\"font-weight: 400;\">Review the security settings of the personal firewall to ensure that it restricts access to specific ports, protects against known attacks, and that there is adequate logging and user alerts in the event of an intrusion.<\/span><\/li>\n<li style=\"font-weight: 400;\"><span style=\"font-weight: 400;\">Ensure that there is a procedure to update the software for any new attacks that become known.<\/span><\/li>\n<\/ul>\n<p><span style=\"font-weight: 400;\">Alternatively, most tools provide the option of transferring automatic updates via the internet. In such instances ensure that updates are received from trusted sites.<\/span><\/p>\n<ol>\n<li style=\"font-weight: 400;\"><span style=\"font-weight: 400;\">Distributed firewalls<\/span><\/li>\n<\/ol>\n<ul>\n<li style=\"font-weight: 400;\"><span style=\"font-weight: 400;\">Ensure that the security policy is consistently distributed to all hosts especially when there are changes to the policy.<\/span><\/li>\n<li style=\"font-weight: 400;\"><span style=\"font-weight: 400;\">Ensure that there are adequate controls to ensure the integrity of the policy during transfer, e.g. IPsec to encrypt the policy when in transfer.<\/span><\/li>\n<li style=\"font-weight: 400;\"><span style=\"font-weight: 400;\">Ensure that there are adequate controls to authenticate the appropriate host.<\/span><\/li>\n<\/ul>\n<p><span style=\"font-weight: 400;\">Again IPsec can be used for authentication with cryptographic certificates.<\/span><\/p>\n<ol>\n<li style=\"font-weight: 400;\"><span style=\"font-weight: 400;\">Continued availability of Firewalls<\/span><\/li>\n<\/ol>\n<ul>\n<li style=\"font-weight: 400;\"><span style=\"font-weight: 400;\">Ensure that there is a hot standby for the primary firewall<\/span><\/li>\n<\/ul>\n<ol>\n<li style=\"font-weight: 400;\"><span style=\"font-weight: 400;\">Network configurations and changes must be documented regularly to understand its structure. Network documentation should include:\u00a0<\/span><\/li>\n<\/ol>\n<ul>\n<li style=\"font-weight: 400;\"><span style=\"font-weight: 400;\">\u00a0Network diagram\u00a0<\/span><\/li>\n<li style=\"font-weight: 400;\"><span style=\"font-weight: 400;\">\u00a0System configurations\u00a0<\/span><\/li>\n<li style=\"font-weight: 400;\"><span style=\"font-weight: 400;\">\u00a0Firewall rule set\u00a0<\/span><\/li>\n<li style=\"font-weight: 400;\"><span style=\"font-weight: 400;\">\u00a0IP Addresses<\/span><\/li>\n<li style=\"font-weight: 400;\"><span style=\"font-weight: 400;\">Access Control Lists<\/span><\/li>\n<\/ul>\n<\/div>\n<\/li>\n<\/ul>\n<div>\n<p>    <base>\n<\/div>\n<p><!-- {\"type\":\"layout\",\"children\":[{\"name\":\"Section1\",\"type\":\"section\",\"props\":{\"width\":\"default\",\"padding\":\"\",\"style\":\"default\",\"header_overlay\":\"\",\"animation\":\"\",\"image_size\":\"cover\",\"image_position\":\"center-center\",\"vertical_align\":\"middle\",\"title_position\":\"top-left\",\"title_rotation\":\"left\",\"title_breakpoint\":\"xl\",\"image_effect\":\"\",\"text_color\":\"\",\"width_expand\":\"\",\"height\":\"\",\"header_transparent\":\"\",\"padding_remove_top\":false,\"padding_remove_bottom\":false},\"children\":[{\"name\":\"\",\"type\":\"row\",\"props\":{\"layout\":\"3-4,1-4\",\"breakpoint\":\"m\",\"fixed_width\":\"large\",\"width\":\"\",\"width_expand\":\"\",\"height\":\"\",\"margin\":\"\",\"column_gap\":\"\",\"row_gap\":\"\",\"order_last\":true},\"children\":[{\"name\":\"\",\"type\":\"column\",\"props\":{\"image_position\":\"center-center\",\"media_overlay_gradient\":\"\"},\"children\":[{\"type\":\"panel\",\"props\":{\"link_text\":\"download<span style=\\\"padding-right:10px;\\\" uk-icon=\\\"arrow-down\\\"><\\\/span>\",\"title_hover_style\":\"reset\",\"title_element\":\"h6\",\"title_align\":\"top\",\"title_grid_width\":\"auto\",\"title_grid_breakpoint\":\"m\",\"meta_style\":\"meta\",\"meta_align\":\"below-title\",\"icon_ratio\":4,\"image_align\":\"left\",\"image_grid_width\":\"auto\",\"image_grid_breakpoint\":\"m\",\"image_svg_color\":\"emphasis\",\"link_style\":\"default\",\"margin\":\"medium\",\"panel_style\":\"card-default\",\"panel_content_padding\":\"\",\"panel_size\":\"\",\"title_style\":\"h6\",\"title_decoration\":\"\",\"title_font_family\":\"\",\"title_color\":\"primary\",\"title_grid_column_gap\":\"\",\"title_grid_row_gap\":\"\",\"title_margin\":\"\",\"meta_color\":\"\",\"meta_margin\":\"\",\"content_style\":\"\",\"content_margin\":\"\",\"image_transition\":\"\",\"image_border\":\"\",\"image_box_shadow\":\"\",\"image_hover_box_shadow\":\"\",\"image_box_decoration\":\"\",\"icon_color\":\"\",\"image_grid_column_gap\":\"\",\"image_grid_row_gap\":\"\",\"image_margin\":\"\",\"link_type\":\"\",\"link_size\":\"\",\"link_margin\":\"\",\"position\":\"\",\"position_z_index\":\"\",\"maxwidth\":\"\",\"maxwidth_breakpoint\":\"\",\"block_align\":\"\",\"block_align_breakpoint\":\"\",\"block_align_fallback\":\"\",\"text_align\":\"\",\"text_align_breakpoint\":\"\",\"text_align_fallback\":\"\",\"animation\":\"\",\"visibility\":\"\",\"title\":\"You can National Information Security & Safety Authority policies as pdf by clicking on this link\",\"content\":\"\",\"image\":\"wp-content\\\/uploads\\\/download-pdf.svg\",\"link\":\"wp-content\\\/uploads\\\/NISSA_Policy_Manual_v1.0-1.pdf\",\"css\":\"\"},\"name\":\"call to action\"},{\"name\":\"\",\"type\":\"headline\",\"props\":{\"title_element\":\"h3\",\"title_style\":\"h3\",\"title_decoration\":\"bullet\",\"text_align\":\"\",\"text_align_breakpoint\":\"\",\"text_align_fallback\":\"\",\"maxwidth\":\"\",\"margin\":\"medium\",\"animation\":\"\",\"visibility\":\"\",\"content\":\"<b>Router and Switch Security Policy<\\\/b>\",\"title_color\":\"\",\"maxwidth_breakpoint\":\"\",\"block_align\":\"\",\"title_font_family\":\"\",\"position\":\"\",\"position_z_index\":\"\",\"block_align_breakpoint\":\"\",\"block_align_fallback\":\"\",\"css\":\".el-element {\\npadding-top: 60px; \\n    margin-top: -20px !important;\\n}\"}},{\"type\":\"grid\",\"props\":{\"show_title\":true,\"show_meta\":true,\"show_content\":true,\"show_image\":true,\"show_link\":true,\"grid_default\":\"1\",\"grid_medium\":\"\",\"filter_style\":\"tab\",\"filter_all\":true,\"filter_position\":\"top\",\"filter_align\":\"left\",\"filter_grid_width\":\"auto\",\"title_element\":\"h4\",\"title_align\":\"top\",\"title_grid_width\":\"1-3\",\"meta_style\":\"meta\",\"meta_align\":\"below-title\",\"icon_ratio\":4,\"image_align\":\"top\",\"image_grid_width\":\"1-2\",\"image_svg_color\":\"emphasis\",\"link_text\":\"Read more\",\"link_style\":\"default\",\"margin\":\"default\",\"item_animation\":\"\",\"grid_small\":\"\",\"grid_large\":\"\",\"grid_xlarge\":\"\",\"filter_margin\":\"\",\"title_display\":\"\",\"content_display\":\"\",\"panel_style\":\"\",\"panel_content_padding\":\"\",\"panel_size\":\"\",\"item_maxwidth\":\"\",\"title_style\":\"h4\",\"title_decoration\":\"\",\"title_color\":\"\",\"title_margin\":\"\",\"meta_color\":\"\",\"meta_margin\":\"\",\"content_style\":\"\",\"content_margin\":\"\",\"image_border\":\"\",\"image_box_shadow\":\"\",\"image_hover_box_shadow\":\"\",\"image_box_decoration\":\"\",\"icon_color\":\"\",\"image_margin\":\"\",\"link_type\":\"\",\"link_size\":\"\",\"link_margin\":\"\",\"text_align\":\"\",\"text_align_breakpoint\":\"\",\"text_align_fallback\":\"\",\"maxwidth\":\"\",\"maxwidth_breakpoint\":\"\",\"visibility\":\"\",\"block_align\":\"\",\"title_hover_style\":\"reset\",\"grid_column_gap\":\"\",\"grid_row_gap\":\"\",\"grid_divider\":false,\"filter_grid_column_gap\":\"\",\"filter_grid_row_gap\":\"\",\"filter_grid_breakpoint\":\"m\",\"title_grid_column_gap\":\"\",\"title_grid_row_gap\":\"\",\"title_grid_breakpoint\":\"m\",\"image_grid_column_gap\":\"\",\"image_grid_row_gap\":\"\",\"image_grid_breakpoint\":\"m\",\"title_font_family\":\"\",\"image_transition\":\"\",\"position\":\"\",\"position_z_index\":\"\",\"block_align_breakpoint\":\"\",\"block_align_fallback\":\"\",\"margin_remove_top\":false,\"margin_remove_bottom\":false},\"children\":[{\"type\":\"grid_item\",\"props\":{\"title\":\"Introduction\",\"content\":\"\n\n<p><span style=\\\"font-weight: 400;\\\">Routers and smart switches provide important security functions within a network. Configured correctly, they are one of several hardware and software devices available that help manage and protect a private network from a public one. The Router and Switch Security Policy defines configuration requirements to meet security standards, change management requirements, and operational requirements.<\\\/span><\\\/p>\"}},{\"type\":\"grid_item\",\"props\":{\"title\":\"Purpose\",\"content\":\"\n\n<p><span style=\\\"font-weight: 400;\\\">This document designed to protect the equipment and data of the <\\\/span><b>(organization)<\\\/b><span style=\\\"font-weight: 400;\\\"> and its business partners or any data the <\\\/span><b>(organization)<\\\/b><span style=\\\"font-weight: 400;\\\"> is in custody of by defining the minimum configuration standards for all routers and switches connecting to the organizational network.<\\\/span><\\\/p>\"}},{\"type\":\"grid_item\",\"props\":{\"title\":\"Scope\",\"content\":\"\n\n<p><span style=\\\"font-weight: 400;\\\">All employees, contractors, consultants, temporary and other workers who use network devices such as Router and\\\/or switch must adhere to this policy. All routers and switches connected to networks are affected.<\\\/span><\\\/p>\"}},{\"type\":\"grid_item\",\"props\":{\"title\":\"Policy\",\"content\":\"\n\n<p class=\\\"p1\\\"><span class=\\\"s1\\\"><span style=\\\"font-weight: 400;\\\">Every router\\\/switch must meet the following configuration standards<\\\/span>:\\u00a0<\\\/span><\\\/p>\\n\n\n<ol class=\\\"ol1\\\">\\n\n\n<li style=\\\"font-weight: 400;\\\"><span style=\\\"font-weight: 400;\\\">No local user accounts are configured on the router or switch. Routers and switches must use a dedicated AAA server (e.g. TACACS+) for all user authentication.<\\\/span><\\\/li>\\n\n\n<li style=\\\"font-weight: 400;\\\"><span style=\\\"font-weight: 400;\\\">The enable secret must be used instead of enable password.<\\\/span><\\\/li>\\n\n\n<li style=\\\"font-weight: 400;\\\"><span style=\\\"font-weight: 400;\\\">The enable secret on the router or switch must be kept in a secure encrypted form.\\u00a0<\\\/span><\\\/li>\\n\n\n<li style=\\\"font-weight: 400;\\\"><span style=\\\"font-weight: 400;\\\">The following services or features must be disabled: <\\\/span><\\\/li>\\n<\\\/ol>\\n\n\n<ul class=\\\"ul1\\\">\\n\n\n<li style=\\\"font-weight: 400;\\\"><span style=\\\"font-weight: 400;\\\">IP directed broadcasts (Enable IP directed broadcast when you want to perform remote management or administration services such as backups on hosts in a subnet that does not have a direct connection to the Internet).<\\\/span><\\\/li>\\n\n\n<li style=\\\"font-weight: 400;\\\"><span style=\\\"font-weight: 400;\\\">Incoming packets at the router\\\/switch sourced with invalid addresses such as RFC1918 addresses.<\\\/span><\\\/li>\\n\n\n<li style=\\\"font-weight: 400;\\\"><span style=\\\"font-weight: 400;\\\">TCP small services\\u00a0<\\\/span><\\\/li>\\n\n\n<li style=\\\"font-weight: 400;\\\"><span style=\\\"font-weight: 400;\\\">UDP small services\\u00a0<\\\/span><\\\/li>\\n\n\n<li style=\\\"font-weight: 400;\\\"><span style=\\\"font-weight: 400;\\\">All web services running on router<\\\/span><\\\/li>\\n\n\n<li style=\\\"font-weight: 400;\\\"><span style=\\\"font-weight: 400;\\\">Auto-configuration.<\\\/span><\\\/li>\\n\n\n<li style=\\\"font-weight: 400;\\\"><span style=\\\"font-weight: 400;\\\">Layer 2 device discovery protocol (e.g. CDP and LLDP) and other discovery protocols.<\\\/span><\\\/li>\\n<\\\/ul>\\n\n\n<p>5. <span style=\\\"font-weight: 400;\\\">Routers and switches and\\\/or interfaces should disallow the following: <\\\/span><span class=\\\"s1\\\"><br \\\/><\\\/span><\\\/p>\\n\n\n<ul class=\\\"ul1\\\">\\n\n\n<li style=\\\"font-weight: 400;\\\"><span style=\\\"font-weight: 400;\\\">Proxy-ARP.<\\\/span><\\\/li>\\n\n\n<li style=\\\"font-weight: 400;\\\"><span style=\\\"font-weight: 400;\\\">ICMP unreachable messages.\\u00a0<\\\/span><\\\/li>\\n\n\n<li style=\\\"font-weight: 400;\\\"><span style=\\\"font-weight: 400;\\\">Fast switching and autonomous switching.\\u00a0<\\\/span><\\\/li>\\n\n\n<li style=\\\"font-weight: 400;\\\"><span style=\\\"font-weight: 400;\\\">Multicast route caching.<\\\/span><\\\/li>\\n\n\n<li style=\\\"font-weight: 400;\\\"><span style=\\\"font-weight: 400;\\\">Maintenance Operation Protocol (MOP).<\\\/span><\\\/li>\\n<\\\/ul>\\n\n\n<p>6. <span style=\\\"font-weight: 400;\\\">The following services must be configured:<\\\/span><span class=\\\"s1\\\"><br \\\/><\\\/span><\\\/p>\\n\n\n<ul class=\\\"ul1\\\">\\n\n\n<li style=\\\"font-weight: 400;\\\"><span style=\\\"font-weight: 400;\\\">Password-encryption<\\\/span><\\\/li>\\n\n\n<li style=\\\"font-weight: 400;\\\"><span style=\\\"font-weight: 400;\\\">Time syncing (NTP). All network clocks should be synced to a common time source.<\\\/span><\\\/li>\\n<\\\/ul>\\n\n\n<p><span style=\\\"font-weight: 400;\\\">7. All routing updates shall be done using secure routing updates.<\\\/span><\\\/p>\\n\n\n<p><span style=\\\"font-weight: 400;\\\">8. Use (<\\\/span><b>organization<\\\/b><span style=\\\"font-weight: 400;\\\">) standardized SNMP community strings.\\u00a0 Default strings, such as public or private must be removed.\\u00a0 SNMP must be configured to use the most secure version of the protocol allowed for by the combination of the device and management systems.<\\\/span><\\\/p>\\n\n\n<p><span style=\\\"font-weight: 400;\\\">9. Access control lists must be used to limit the source and type of traffic that can terminate on the device itself.<\\\/span><\\\/p>\\n\n\n<p><span style=\\\"font-weight: 400;\\\">10. Each router must have a Login banners that useful to inform potential users that use of the login is only for authorized users. the following statement presented for all forms of login whether remote or local:\\u00a0<\\\/span><\\\/p>\\n\n\n<p><span style=\\\"font-weight: 400;\\\">\\\"UNAUTHORIZED ACCESS TO THIS NETWORK DEVICE IS PROHIBITED.<\\\/span><\\\/p>\\n\n\n<p><span style=\\\"font-weight: 400;\\\">You must have explicit permission to access or configure this device. All activities performed on this device may be logged, and violations of this policy may result in disciplinary action in accordance with regulation in force. There is no right to privacy on this device. Use of this system shall constitute consent to monitoring.\\\"<\\\/span><\\\/p>\\n\n\n<p>\\u00a0<\\\/p>\\n\n\n<p><span style=\\\"font-weight: 400;\\\">11. Telnet may never be used across any network to manage a router, unless there is a secure tunnel protecting the entire communication path. SSH version 2 is the preferred management protocol.<\\\/span><\\\/p>\\n\n\n<p><span style=\\\"font-weight: 400;\\\">12. Routers and switches should be placed in a location where physical access is limited to authorized persons only.<\\\/span><\\\/p>\\n\n\n<p><span style=\\\"font-weight: 400;\\\">13. The switch should disable a port or group of ports if new or unregistered MAC addresses appear on a port if the feature is available.<\\\/span><\\\/p>\\n\n\n<p><span style=\\\"font-weight: 400;\\\">14. The\\u00a0 switch\\u00a0 should generate\\u00a0 an SNMP trap if the\\u00a0 link drops and is re-established\\u00a0 if the feature is available<\\\/span><\\\/p>\\n\n\n<p><span style=\\\"font-weight: 400;\\\">15. Dynamic routing protocols must use authentication in routing updates sent to neighbors.\\u00a0 (<\\\/span><b><i>Password hashing for the authentication string must be enabled when supported<\\\/i><\\\/b><span style=\\\"font-weight: 400;\\\">).<\\\/span><\\\/p>\\n\n\n<p><span style=\\\"font-weight: 400;\\\">16. The (<\\\/span><b>organization<\\\/b><span style=\\\"font-weight: 400;\\\">) router configuration standard will define the category of sensitive routing and switching devices, and require additional services or configuration on sensitive devices including:<\\\/span><\\\/p>\\n\n\n<ul>\\n\n\n<li style=\\\"font-weight: 400;\\\"><span style=\\\"font-weight: 400;\\\">IP access list accounting<\\\/span><\\\/li>\\n\n\n<li style=\\\"font-weight: 400;\\\"><span style=\\\"font-weight: 400;\\\">Device logging<\\\/span><\\\/li>\\n\n\n<li style=\\\"font-weight: 400;\\\"><span style=\\\"font-weight: 400;\\\">Incoming packets at the router sourced with invalid addresses, such as RFC1918 addresses, or those that could be used to spoof network traffic shall be dropped.<\\\/span><\\\/li>\\n<\\\/ul>\\n\n\n<p><span style=\\\"font-weight: 400;\\\">17. Network configurations and changes must be documented regularly to understand its structure. Network documentation should include:\\u00a0<\\\/span><\\\/p>\\n\n\n<ul>\\n\n\n<li style=\\\"font-weight: 400;\\\"><span style=\\\"font-weight: 400;\\\">\\u00a0Network diagram\\u00a0<\\\/span><\\\/li>\\n\n\n<li style=\\\"font-weight: 400;\\\"><span style=\\\"font-weight: 400;\\\">\\u00a0System configurations\\u00a0<\\\/span><\\\/li>\\n\n\n<li style=\\\"font-weight: 400;\\\"><span style=\\\"font-weight: 400;\\\">\\u00a0Firewall rule set\\u00a0<\\\/span><\\\/li>\\n\n\n<li style=\\\"font-weight: 400;\\\"><span style=\\\"font-weight: 400;\\\">\\u00a0IP Addresses<\\\/span><\\\/li>\\n\n\n<li style=\\\"font-weight: 400;\\\"><span style=\\\"font-weight: 400;\\\">Access Control Lists<\\\/span><\\\/li>\\n<\\\/ul>\\n\n\n<ul class=\\\"ul1\\\">\\n\n\n<li class=\\\"li2\\\" style=\\\"list-style-type: none;\\\">\\u00a0<\\\/li>\\n<\\\/ul>\"}}]},{\"name\":\"\",\"type\":\"headline\",\"props\":{\"title_element\":\"h2\",\"title_style\":\"h2\",\"title_decoration\":\"bullet\",\"text_align\":\"\",\"text_align_breakpoint\":\"\",\"text_align_fallback\":\"\",\"maxwidth\":\"\",\"margin\":\"medium\",\"animation\":\"\",\"visibility\":\"\",\"content\":\"<b>Wireless Communication Policy<\\\/b>\",\"title_color\":\"\",\"maxwidth_breakpoint\":\"\",\"block_align\":\"\",\"title_font_family\":\"\",\"position\":\"\",\"position_z_index\":\"\",\"block_align_breakpoint\":\"\",\"block_align_fallback\":\"\",\"css\":\".el-element {\\npadding-top: 60px; \\n    margin-top: -20px !important;\\n}\"}},{\"type\":\"grid\",\"props\":{\"show_title\":true,\"show_meta\":true,\"show_content\":true,\"show_image\":true,\"show_link\":true,\"grid_default\":\"1\",\"grid_medium\":\"\",\"filter_style\":\"tab\",\"filter_all\":true,\"filter_position\":\"top\",\"filter_align\":\"left\",\"filter_grid_width\":\"auto\",\"title_element\":\"h3\",\"title_align\":\"top\",\"title_grid_width\":\"1-3\",\"meta_style\":\"meta\",\"meta_align\":\"below-title\",\"icon_ratio\":4,\"image_align\":\"top\",\"image_grid_width\":\"1-2\",\"image_svg_color\":\"emphasis\",\"link_text\":\"Read more\",\"link_style\":\"default\",\"margin\":\"default\",\"item_animation\":\"\",\"grid_small\":\"\",\"grid_large\":\"\",\"grid_xlarge\":\"\",\"filter_margin\":\"\",\"title_display\":\"\",\"content_display\":\"\",\"panel_style\":\"\",\"panel_content_padding\":\"\",\"panel_size\":\"\",\"item_maxwidth\":\"\",\"title_style\":\"h3\",\"title_decoration\":\"\",\"title_color\":\"\",\"title_margin\":\"\",\"meta_color\":\"\",\"meta_margin\":\"\",\"content_style\":\"\",\"content_margin\":\"\",\"image_border\":\"\",\"image_box_shadow\":\"\",\"image_hover_box_shadow\":\"\",\"image_box_decoration\":\"\",\"icon_color\":\"\",\"image_margin\":\"\",\"link_type\":\"\",\"link_size\":\"\",\"link_margin\":\"\",\"text_align\":\"\",\"text_align_breakpoint\":\"\",\"text_align_fallback\":\"\",\"maxwidth\":\"\",\"maxwidth_breakpoint\":\"\",\"visibility\":\"\",\"block_align\":\"\",\"title_hover_style\":\"reset\",\"grid_column_gap\":\"\",\"grid_row_gap\":\"\",\"grid_divider\":false,\"filter_grid_column_gap\":\"\",\"filter_grid_row_gap\":\"\",\"filter_grid_breakpoint\":\"m\",\"title_grid_column_gap\":\"\",\"title_grid_row_gap\":\"\",\"title_grid_breakpoint\":\"m\",\"image_grid_column_gap\":\"\",\"image_grid_row_gap\":\"\",\"image_grid_breakpoint\":\"m\",\"title_font_family\":\"\",\"image_transition\":\"\",\"position\":\"\",\"position_z_index\":\"\",\"block_align_breakpoint\":\"\",\"block_align_fallback\":\"\",\"margin_remove_top\":true,\"margin_remove_bottom\":true},\"children\":[{\"type\":\"grid_item\",\"props\":{\"title\":\"Introduction\",\"content\":\"\n\n<p><span style=\\\"font-weight: 400;\\\">With the mass explosion of Smart Phones and Tablets, pervasive wireless connectivity is almost a given at any organization. Insecure wireless configuration can provide an easy open door for malicious threat actors.\\u00a0<\\\/span><\\\/p>\\n\n\n<p><span style=\\\"font-weight: 400;\\\">A Wireless Communication Policy is necessary for computer security since there is demand for wireless equipment in every (<\\\/span><b>organization<\\\/b><span style=\\\"font-weight: 400;\\\">) today. The Wireless Communication Policy may specify that no wireless equipment should be used but this would not be very good since that may cause some departments or individuals to violate the policy. It is best to set conditions and specify equipment that is approved for wireless use in order to minimize security risk associated with wireless.<\\\/span><\\\/p>\"}},{\"type\":\"grid_item\",\"props\":{\"title\":\"Purpose\",\"content\":\"\n\n<p><span style=\\\"font-weight: 400;\\\">The purpose of this policy is to secure and protect the information assets owned by <\\\/span><b>(Organization)<\\\/b><span style=\\\"font-weight: 400;\\\">. <\\\/span><b>(Organization)<\\\/b><span style=\\\"font-weight: 400;\\\"> grants access to these resources as a privilege and must manage them responsibly to maintain the confidentiality, integrity, and availability of all information assets.<\\\/span><\\\/p>\\n\n\n<p><span style=\\\"font-weight: 400;\\\">This policy specifies the conditions that wireless infrastructure devices must satisfy to connect to <\\\/span><b>(Organization)<\\\/b><span style=\\\"font-weight: 400;\\\"> network. Only <\\\/span><b>those<\\\/b><span style=\\\"font-weight: 400;\\\"> wireless infrastructure devices that meet the standards <\\\/span><b>specified in<\\\/b><span style=\\\"font-weight: 400;\\\">\\u00a0this policy, or that granted an exception by the Information Security Department are approved for connectivity to a <\\\/span><b>(Organization)<\\\/b><span style=\\\"font-weight: 400;\\\"> network.<\\\/span><\\\/p>\"}},{\"type\":\"grid_item\",\"props\":{\"title\":\"Scope\",\"content\":\"\n\n<p><span style=\\\"font-weight: 400;\\\">This policy applies to all wireless infrastructure devices that connect to a <\\\/span><b>(Organization)<\\\/b><span style=\\\"font-weight: 400;\\\"> network or reside on a <\\\/span><b>(Organization)<\\\/b><span style=\\\"font-weight: 400;\\\"> site that provide wireless connectivity to endpoint devices including, but not limited to, laptops, desktops, cellular phones, and tablets. This includes any form of wireless communication device capable of transmitting packet data .Therefore, all employees, contractors, consultants, temporary and other workers at <\\\/span><b>(Organization)<\\\/b><span style=\\\"font-weight: 400;\\\">, including all personnel affiliated with third parties that maintain a wireless infrastructure device on behalf of <\\\/span><b>(Organization)<\\\/b><span style=\\\"font-weight: 400;\\\"> must adhere to this policy.<\\\/span><\\\/p>\"}},{\"type\":\"grid_item\",\"props\":{\"title\":\"Policy\",\"content\":\"\n\n<p><span style=\\\"font-weight: 400;\\\">All wireless infrastructure devices that reside at a <\\\/span><b>(Organization)<\\\/b><span style=\\\"font-weight: 400;\\\"> site and connect to a (Organization) network, or provide access to information classified as <\\\/span><b>(Organization)<\\\/b><span style=\\\"font-weight: 400;\\\"> Confidential, or above must:\\u00a0<\\\/span><\\\/p>\\n\n\n<ul>\\n\n\n<li style=\\\"font-weight: 400;\\\"><span style=\\\"font-weight: 400;\\\">Abide by the standards specified in the Wireless Communication Standard.\\u00a0<\\\/span><\\\/li>\\n\n\n<li style=\\\"font-weight: 400;\\\"><span style=\\\"font-weight: 400;\\\">Use <\\\/span><b>(Organization)<\\\/b><span style=\\\"font-weight: 400;\\\"> approved authentication protocols and infrastructure.<\\\/span><\\\/li>\\n\n\n<li style=\\\"font-weight: 400;\\\"><span style=\\\"font-weight: 400;\\\">Use <\\\/span><b>(Organization)<\\\/b><span style=\\\"font-weight: 400;\\\"> approved encryption protocols.<\\\/span><\\\/li>\\n\n\n<li style=\\\"font-weight: 400;\\\"><span style=\\\"font-weight: 400;\\\">Maintain a hardware address (MAC address) that can be registered and tracked.\\u00a0<\\\/span><\\\/li>\\n<\\\/ul>\\n\n\n<p><span style=\\\"font-weight: 400;\\\">To stop the possible abuse of wireless network:<\\\/span><\\\/p>\\n\n\n<ul>\\n\n\n<li style=\\\"font-weight: 400;\\\"><span style=\\\"font-weight: 400;\\\">There should be proper user authentication ensured along with the appropriate replacement of WEP and anomaly tracking mechanism on wireless LAN.\\u00a0<\\\/span><\\\/li>\\n\n\n<li style=\\\"font-weight: 400;\\\"><span style=\\\"font-weight: 400;\\\">At the same time, there is the following list of suspicious events on wireless LAN which should always consider for intrusion detection as;<\\\/span><\\\/li>\\n<\\\/ul>\\n\n\n<ul>\\n\n\n<li style=\\\"font-weight: 400;\\\"><span style=\\\"font-weight: 400;\\\">Beacon frames from unsolicited access point<\\\/span><\\\/li>\\n\n\n<li style=\\\"font-weight: 400;\\\"><span style=\\\"font-weight: 400;\\\">Flood of unauthenticated frames (MITM attack)<\\\/span><\\\/li>\\n\n\n<li style=\\\"font-weight: 400;\\\"><span style=\\\"font-weight: 400;\\\">Frames with duplicated MAC address.<\\\/span><\\\/li>\\n\n\n<li style=\\\"font-weight: 400;\\\"><span style=\\\"font-weight: 400;\\\">Randomly changing MAC address<\\\/span><\\\/li>\\n<\\\/ul>\\n\n\n<p><span style=\\\"font-weight: 400;\\\">Wireless encryption protocols\\u00a0<\\\/span><\\\/p>\\n\n\n<ul>\\n\n\n<li style=\\\"font-weight: 400;\\\"><span style=\\\"font-weight: 400;\\\">WAP2 (Wi-Fi Protected Access version 2) is preferred as a wireless encryption protocol instead of WEP (Wired Equivalent Privacy) and WAP (Wi-Fi Protected Access\\u00a0), because WAP2 It offered a much stronger security algorithm and advanced level encryption with message authenticity and integrity validation while WEP\\u00a0and\\u00a0WPA\\u00a0protocols are considered vulnerable.<\\\/span><\\\/li>\\n<\\\/ul>\\n\n\n<p><span style=\\\"font-weight: 400;\\\">Network configurations and changes must be documented regularly to understand its structure. Network documentation should include:\\u00a0<\\\/span><\\\/p>\\n\n\n<ul>\\n\n\n<li style=\\\"font-weight: 400;\\\"><span style=\\\"font-weight: 400;\\\">Network diagram\\u00a0<\\\/span><\\\/li>\\n\n\n<li style=\\\"font-weight: 400;\\\"><span style=\\\"font-weight: 400;\\\">System configurations\\u00a0<\\\/span><\\\/li>\\n\n\n<li style=\\\"font-weight: 400;\\\"><span style=\\\"font-weight: 400;\\\">\\u00a0Firewall rule set\\u00a0<\\\/span><\\\/li>\\n\n\n<li style=\\\"font-weight: 400;\\\"><span style=\\\"font-weight: 400;\\\">\\u00a0IP Addresses<\\\/span><\\\/li>\\n\n\n<li style=\\\"font-weight: 400;\\\"><span style=\\\"font-weight: 400;\\\">Access Control Lists<\\\/span><\\\/li>\\n<\\\/ul>\"}}]},{\"name\":\"\",\"type\":\"headline\",\"props\":{\"title_element\":\"h2\",\"title_style\":\"h2\",\"title_decoration\":\"bullet\",\"text_align\":\"\",\"text_align_breakpoint\":\"\",\"text_align_fallback\":\"\",\"maxwidth\":\"\",\"margin\":\"medium\",\"animation\":\"\",\"visibility\":\"\",\"content\":\"<b>Virtual Private Network (VPN) Policy<\\\/b>\",\"title_color\":\"\",\"maxwidth_breakpoint\":\"\",\"block_align\":\"\",\"title_font_family\":\"\",\"position\":\"\",\"position_z_index\":\"\",\"block_align_breakpoint\":\"\",\"block_align_fallback\":\"\",\"css\":\".el-element {\\npadding-top: 60px; \\n    margin-top: -20px !important;\\n}\"}},{\"type\":\"grid\",\"props\":{\"show_title\":true,\"show_meta\":true,\"show_content\":true,\"show_image\":true,\"show_link\":true,\"grid_default\":\"1\",\"grid_medium\":\"\",\"filter_style\":\"tab\",\"filter_all\":true,\"filter_position\":\"top\",\"filter_align\":\"left\",\"filter_grid_width\":\"auto\",\"title_element\":\"h3\",\"title_align\":\"top\",\"title_grid_width\":\"1-3\",\"meta_style\":\"meta\",\"meta_align\":\"below-title\",\"icon_ratio\":4,\"image_align\":\"top\",\"image_grid_width\":\"1-2\",\"image_svg_color\":\"emphasis\",\"link_text\":\"Read more\",\"link_style\":\"default\",\"margin\":\"default\",\"item_animation\":\"\",\"grid_small\":\"\",\"grid_large\":\"\",\"grid_xlarge\":\"\",\"filter_margin\":\"\",\"title_display\":\"\",\"content_display\":\"\",\"panel_style\":\"\",\"panel_content_padding\":\"\",\"panel_size\":\"\",\"item_maxwidth\":\"\",\"title_style\":\"h3\",\"title_decoration\":\"\",\"title_color\":\"\",\"title_margin\":\"\",\"meta_color\":\"\",\"meta_margin\":\"\",\"content_style\":\"\",\"content_margin\":\"\",\"image_border\":\"\",\"image_box_shadow\":\"\",\"image_hover_box_shadow\":\"\",\"image_box_decoration\":\"\",\"icon_color\":\"\",\"image_margin\":\"\",\"link_type\":\"\",\"link_size\":\"\",\"link_margin\":\"\",\"text_align\":\"\",\"text_align_breakpoint\":\"\",\"text_align_fallback\":\"\",\"maxwidth\":\"\",\"maxwidth_breakpoint\":\"\",\"visibility\":\"\",\"block_align\":\"\",\"title_hover_style\":\"reset\",\"grid_column_gap\":\"\",\"grid_row_gap\":\"\",\"grid_divider\":false,\"filter_grid_column_gap\":\"\",\"filter_grid_row_gap\":\"\",\"filter_grid_breakpoint\":\"m\",\"title_grid_column_gap\":\"\",\"title_grid_row_gap\":\"\",\"title_grid_breakpoint\":\"m\",\"image_grid_column_gap\":\"\",\"image_grid_row_gap\":\"\",\"image_grid_breakpoint\":\"m\",\"title_font_family\":\"\",\"image_transition\":\"\",\"position\":\"\",\"position_z_index\":\"\",\"block_align_breakpoint\":\"\",\"block_align_fallback\":\"\",\"margin_remove_top\":true,\"margin_remove_bottom\":true},\"children\":[{\"type\":\"grid_item\",\"props\":{\"title\":\"Introduction\",\"content\":\"\n\n<p><span style=\\\"font-weight: 400;\\\">A Virtual Private Network (VPN) is a secured private network connection that provide a convenient way to access internal network resources remotely over the public network (Internet). VPN offers secure access by providing a means to protect data while it travels over an untrusted network. <\\\/span><\\\/p>\"}},{\"type\":\"grid_item\",\"props\":{\"title\":\"Purpose\",\"content\":\"\n\n<p><span style=\\\"font-weight: 400;\\\">The purpose of this policy is to provide guidelines for Remote Access IPsec or L2TP Virtual Private Network (VPN) connections to the <\\\/span><b>(Organization)<\\\/b><span style=\\\"font-weight: 400;\\\"> corporate network.\\u00a0 <\\\/span><\\\/p>\"}},{\"type\":\"grid_item\",\"props\":{\"title\":\"Scope\",\"content\":\"\n\n<p><span style=\\\"font-weight: 400;\\\">This policy applies to all <\\\/span><b>(Organization)<\\\/b><span style=\\\"font-weight: 400;\\\"> employees, contractors, consultants, temporaries, and other workers including all personnel affiliated with third parties utilizing VPNs to access the <\\\/span><b>(Organization)<\\\/b><span style=\\\"font-weight: 400;\\\"> network. This policy applies to implementations of VPN that are directed through an IPsec Concentrator. <\\\/span><\\\/p>\"}},{\"type\":\"grid_item\",\"props\":{\"title\":\"Policy\",\"content\":\"\n\n<ol>\\n\n\n<li><span style=\\\"font-weight: 400;\\\">It is the responsibility of employees with VPN privileges to ensure that unauthorized users are not allowed access to <\\\/span><b>(Organization)<\\\/b><span style=\\\"font-weight: 400;\\\"> internal networks through their VPN connection.\\u00a0<\\\/span><\\\/li>\\n\n\n<li><span style=\\\"font-weight: 400;\\\">VPN use is to be controlled using either a one-time password authentication such as a token device or a public\\\/private key system with a strong passphrase.\\u00a0<\\\/span><\\\/li>\\n\n\n<li><span style=\\\"font-weight: 400;\\\">When actively connected to the corporate network, VPNs will force all traffic to and from the PC used by the remote user over the VPN tunnel: all other traffic will be dropped.\\u00a0<\\\/span><\\\/li>\\n\n\n<li><span style=\\\"font-weight: 400;\\\">Dual (split) tunneling is NOT permitted; only one network connection is allowed.\\u00a0 [<\\\/span><i><span style=\\\"font-weight: 400;\\\">Dual (split) tunneling allows two simultaneous, active connections to a secure network (via VPN) and a non-secure network, without having to disconnect the VPN connection. This security vulnerability allows a direct connection from the non-secured Internet to the VPN secured network.<\\\/span><\\\/i><span style=\\\"font-weight: 400;\\\">]<\\\/span><\\\/li>\\n\n\n<li><span style=\\\"font-weight: 400;\\\">VPN gateways will be set up and managed by <\\\/span><b>(Organization)<\\\/b><span style=\\\"font-weight: 400;\\\"> network operational groups.\\u00a0<\\\/span><\\\/li>\\n\n\n<li><span style=\\\"font-weight: 400;\\\">All computers connected to <\\\/span><b>(Organization)<\\\/b><span style=\\\"font-weight: 400;\\\"> internal networks via VPN or any other technology must use the most up-to-date anti-virus software that is the corporate standard (provide URL to this software); this includes <\\\/span><span style=\\\"font-weight: 400;\\\">personal computers.\\u00a0<\\\/span><\\\/li>\\n\n\n<li><span style=\\\"font-weight: 400;\\\">VPN users will be automatically disconnected from <\\\/span><b>(Organization)<\\\/b><span style=\\\"font-weight: 400;\\\">'s network after thirty minutes of inactivity. The user must then logon again to reconnect to the network. <\\\/span><i><span>(Pings or other artificial network processes are not to be used to keep the connection open.)\\u00a0<\\\/span><\\\/i><\\\/li>\\n\n\n<li><span style=\\\"font-weight: 400;\\\">The VPN concentrator must be limited to an absolute connection time of 24 hours.\\u00a0<\\\/span><\\\/li>\\n\n\n<li><span style=\\\"font-weight: 400;\\\">Users of computers that are not <\\\/span><b>(Organization)<\\\/b><span style=\\\"font-weight: 400;\\\">-owned equipment must configure the equipment to comply with <\\\/span><b>(Organization)<\\\/b><span style=\\\"font-weight: 400;\\\">'s VPN and Network policies.\\u00a0<\\\/span><\\\/li>\\n\n\n<li><span style=\\\"font-weight: 400;\\\">By using VPN technology with personal equipment, users must understand that their machines are a de facto extension of <\\\/span><b>(Organization)<\\\/b><span style=\\\"font-weight: 400;\\\">'s network, and as such are subject to the same rules and regulations that apply to <\\\/span><b>(Organization)<\\\/b><span style=\\\"font-weight: 400;\\\">-owned equipment.<\\\/span><\\\/li>\\n\n\n<li><span style=\\\"font-weight: 400;\\\">Network configurations and changes must be documented regularly to understand its structure. Network documentation should include:\\u00a0<\\\/span><\\\/li>\\n<\\\/ol>\\n\n\n<ul>\\n\n\n<li style=\\\"list-style-type: none;\\\">\\n\n\n<ul>\\n\n\n<li><span style=\\\"font-weight: 400;\\\">\\u00a0Network diagram\\u00a0<\\\/span><\\\/li>\\n\n\n<li><span style=\\\"font-weight: 400;\\\">\\u00a0System configurations\\u00a0<\\\/span><\\\/li>\\n\n\n<li><span style=\\\"font-weight: 400;\\\">\\u00a0Firewall rule set\\u00a0<\\\/span><\\\/li>\\n\n\n<li><span style=\\\"font-weight: 400;\\\">\\u00a0IP Addresses<\\\/span><\\\/li>\\n\n\n<li><span style=\\\"font-weight: 400;\\\">Access Control Lists<\\\/span><\\\/li>\\n<\\\/ul>\\n<\\\/li>\\n<\\\/ul>\"}}]},{\"name\":\"\",\"type\":\"headline\",\"props\":{\"title_element\":\"h2\",\"title_style\":\"h2\",\"title_decoration\":\"bullet\",\"text_align\":\"\",\"text_align_breakpoint\":\"\",\"text_align_fallback\":\"\",\"maxwidth\":\"\",\"margin\":\"medium\",\"animation\":\"\",\"visibility\":\"\",\"content\":\"<b>Firewall Policy<\\\/b>\",\"title_color\":\"\",\"maxwidth_breakpoint\":\"\",\"block_align\":\"\",\"title_font_family\":\"\",\"position\":\"\",\"position_z_index\":\"\",\"block_align_breakpoint\":\"\",\"block_align_fallback\":\"\"}},{\"type\":\"grid\",\"props\":{\"show_title\":true,\"show_meta\":true,\"show_content\":true,\"show_image\":true,\"show_link\":true,\"grid_default\":\"1\",\"grid_medium\":\"\",\"filter_style\":\"tab\",\"filter_all\":true,\"filter_position\":\"top\",\"filter_align\":\"left\",\"filter_grid_width\":\"auto\",\"title_element\":\"h3\",\"title_align\":\"top\",\"title_grid_width\":\"1-3\",\"meta_style\":\"meta\",\"meta_align\":\"below-title\",\"icon_ratio\":4,\"image_align\":\"top\",\"image_grid_width\":\"1-2\",\"image_svg_color\":\"emphasis\",\"link_text\":\"Read more\",\"link_style\":\"default\",\"margin\":\"default\",\"item_animation\":\"\",\"grid_small\":\"\",\"grid_large\":\"\",\"grid_xlarge\":\"\",\"filter_margin\":\"\",\"title_display\":\"\",\"content_display\":\"\",\"panel_style\":\"\",\"panel_content_padding\":\"\",\"panel_size\":\"\",\"item_maxwidth\":\"\",\"title_style\":\"h3\",\"title_decoration\":\"\",\"title_color\":\"\",\"title_margin\":\"\",\"meta_color\":\"\",\"meta_margin\":\"\",\"content_style\":\"\",\"content_margin\":\"\",\"image_border\":\"\",\"image_box_shadow\":\"\",\"image_hover_box_shadow\":\"\",\"image_box_decoration\":\"\",\"icon_color\":\"\",\"image_margin\":\"\",\"link_type\":\"\",\"link_size\":\"\",\"link_margin\":\"\",\"text_align\":\"\",\"text_align_breakpoint\":\"\",\"text_align_fallback\":\"\",\"maxwidth\":\"\",\"maxwidth_breakpoint\":\"\",\"visibility\":\"\",\"block_align\":\"\",\"title_hover_style\":\"reset\",\"grid_column_gap\":\"\",\"grid_row_gap\":\"\",\"grid_divider\":false,\"filter_grid_column_gap\":\"\",\"filter_grid_row_gap\":\"\",\"filter_grid_breakpoint\":\"m\",\"title_grid_column_gap\":\"\",\"title_grid_row_gap\":\"\",\"title_grid_breakpoint\":\"m\",\"image_grid_column_gap\":\"\",\"image_grid_row_gap\":\"\",\"image_grid_breakpoint\":\"m\",\"title_font_family\":\"\",\"image_transition\":\"\",\"position\":\"\",\"position_z_index\":\"\",\"block_align_breakpoint\":\"\",\"block_align_fallback\":\"\",\"margin_remove_top\":true,\"margin_remove_bottom\":true},\"children\":[{\"type\":\"grid_item\",\"props\":{\"title\":\"Introduction\",\"content\":\"\n\n<p><span style=\\\"font-weight: 400;\\\">When a user connects to an insecure, open network, such as the Internet, he opens a large doorway for potential attacks. One of the best ways to defense against exploitation from the insecure network is to employ firewalls at the connection point end, as it is a necessity to safeguard the<\\\/span> <b>(Organization)<\\\/b><span style=\\\"font-weight: 400;\\\">\\u2019s private networks and communication facilities. <\\\/span><\\\/p>\"}},{\"type\":\"grid_item\",\"props\":{\"title\":\"Purpose\",\"content\":\"\n\n<p><span style=\\\"font-weight: 400;\\\">Firewalls are defined as security systems that control and restrict network connectivity and network services. Firewalls establish a control point where access controls may be enforced. This document seeks to assist <\\\/span><b>(Organization)<\\\/b><span style=\\\"font-weight: 400;\\\"> in understanding the capabilities of firewall technologies and firewall policies.<\\\/span><\\\/p>\"}},{\"type\":\"grid_item\",\"props\":{\"title\":\"Scope\",\"content\":\"\n\n<p><span style=\\\"font-weight: 400;\\\">This policy defines the essential rules regarding the management and maintenance of firewalls, and it applies to all firewalls owned, rented, leased, or otherwise controlled by <\\\/span><b>(Organization)<\\\/b><span style=\\\"font-weight: 400;\\\">.<\\\/span><\\\/p>\"}},{\"type\":\"grid_item\",\"props\":{\"title\":\"\",\"content\":\"\n\n<ol>\\n\n\n<li style=\\\"font-weight: 400;\\\"><span style=\\\"font-weight: 400;\\\">Review the rulesets to ensure that they follow the order as follows:<\\\/span><\\\/li>\\n<\\\/ol>\\n\n\n<ul>\\n\n\n<li style=\\\"list-style-type: none;\\\">\\n\n\n<ul>\\n\n\n<li style=\\\"font-weight: 400;\\\"><span style=\\\"font-weight: 400;\\\">anti-spoofing filters (blocked private addresses, internal addresses appearing from the outside)<\\\/span><\\\/li>\\n\n\n<li style=\\\"font-weight: 400;\\\"><span style=\\\"font-weight: 400;\\\">User permit rules (e.g. allow HTTP to public webserver)<\\\/span><\\\/li>\\n\n\n<li style=\\\"font-weight: 400;\\\"><span style=\\\"font-weight: 400;\\\">Management permit rules (e.g. SNMP traps to network management server)<\\\/span><\\\/li>\\n\n\n<li style=\\\"font-weight: 400;\\\"><span style=\\\"font-weight: 400;\\\">Deny and Alert (alert systems administrator about traffic that is suspicious)<\\\/span><\\\/li>\\n\n\n<li style=\\\"font-weight: 400;\\\"><span style=\\\"font-weight: 400;\\\">Deny and log (log remaining traffic for analysis)<\\\/span><\\\/li>\\n<\\\/ul>\\n<\\\/li>\\n<\\\/ul>\\n\n\n<ol>\\n\n\n<li style=\\\"font-weight: 400;\\\"><span style=\\\"font-weight: 400;\\\">\\u00a0Application based firewall:<\\\/span><\\\/li>\\n<\\\/ol>\\n\n\n<ul>\\n\n\n<li style=\\\"list-style-type: none;\\\">\\n\n\n<ul>\\n\n\n<li><span style=\\\"font-weight: 400;\\\">In the case of dedicated server access, an <\\\/span><b>application proxy firewall<\\\/b><span style=\\\"font-weight: 400;\\\"> must be placed between the remote user and dedicated server to hide the identity of the server.<\\\/span><\\\/li>\\n\n\n<li><span style=\\\"font-weight: 400;\\\">Ensure that the administrators monitor any attempts to violate the security policy using the audit logs generated by the application level firewall.<\\\/span><\\\/li>\\n\n\n<li><span style=\\\"font-weight: 400;\\\">Ensure that there is a process to update the application level firewall\\u2019s vulnerabilities checked to the most current vulnerabilities.<\\\/span><\\\/li>\\n\n\n<li><span style=\\\"font-weight: 400;\\\">Ensure that there is a process to update the software with the latest attack signatures.<\\\/span><\\\/li>\\n\n\n<li><span style=\\\"font-weight: 400;\\\">In the event of the signatures being downloaded from the vendors\\u2019 site, ensure that it is a trusted site.<\\\/span><\\\/li>\\n\n\n<li><span style=\\\"font-weight: 400;\\\">In the event of the signature being e-mailed to the systems administrator, ensure that digital signatures are used to verify the vendor and that the information transmitted has not been modified en-route.<\\\/span><\\\/li>\\n\n\n<li><span style=\\\"font-weight: 400;\\\">The following commands should be blocked for SMTP at the application level firewall:<\\\/span>\\n\n\n<ul>\\n\n\n<li style=\\\"font-weight: 400;\\\"><span style=\\\"font-weight: 400;\\\">EXPN (expand)<\\\/span><\\\/li>\\n\n\n<li style=\\\"font-weight: 400;\\\"><span style=\\\"font-weight: 400;\\\">VRFY (verify)<\\\/span><\\\/li>\\n\n\n<li style=\\\"font-weight: 400;\\\"><span style=\\\"font-weight: 400;\\\">DEBUG<\\\/span><\\\/li>\\n\n\n<li style=\\\"font-weight: 400;\\\"><span style=\\\"font-weight: 400;\\\">WIZARD<\\\/span><\\\/li>\\n<\\\/ul>\\n<\\\/li>\\n<\\\/ul>\\n<\\\/li>\\n<\\\/ul>\\n\n\n<ul>\\n\n\n<li style=\\\"list-style-type: none;\\\">\\n\n\n<ul>\\n\n\n<li style=\\\"font-weight: 400;\\\"><span style=\\\"font-weight: 400;\\\">The following command should be blocked for FTP:<\\\/span><\\\/li>\\n<\\\/ul>\\n<\\\/li>\\n<\\\/ul>\\n\n\n<ul>\\n\n\n<li style=\\\"list-style-type: none;\\\">\\n\n\n<ul>\\n\n\n<li style=\\\"list-style-type: none;\\\">\\n\n\n<ul>\\n\n\n<li style=\\\"font-weight: 400;\\\"><span style=\\\"font-weight: 400;\\\">PUT<\\\/span><\\\/li>\\n<\\\/ul>\\n<\\\/li>\\n<\\\/ul>\\n<\\\/li>\\n<\\\/ul>\\n\n\n<ul>\\n\n\n<li style=\\\"list-style-type: none;\\\">\\n\n\n<ul>\\n\n\n<li style=\\\"font-weight: 400;\\\"><span style=\\\"font-weight: 400;\\\">Review the denied URL\\u2019s and ensure that they are appropriate for e.g. any URL\\u2019s to hacker sites should be blocked.\\u00a0<\\\/span><\\\/li>\\n\n\n<li style=\\\"font-weight: 400;\\\"><span style=\\\"font-weight: 400;\\\">Ensure that only authorized users are authenticated by the application level firewall.<\\\/span><\\\/li>\\n<\\\/ul>\\n<\\\/li>\\n<\\\/ul>\\n\n\n<ol>\\n\n\n<li style=\\\"font-weight: 400;\\\"><span style=\\\"font-weight: 400;\\\">Stateful inspection<\\\/span><\\\/li>\\n<\\\/ol>\\n\n\n<ul>\\n\n\n<li style=\\\"list-style-type: none;\\\">\\n\n\n<ul>\\n\n\n<li style=\\\"font-weight: 400;\\\"><span style=\\\"font-weight: 400;\\\">Review the state tables to ensure that appropriate rules are set up in terms of source and destination IP\\u2019s, source and destination ports and timeouts.<\\\/span><\\\/li>\\n\n\n<li style=\\\"font-weight: 400;\\\"><span style=\\\"font-weight: 400;\\\">Ensure that the timeouts are appropriate so as not to give the hacker too much time to launch a successful attack.<\\\/span><\\\/li>\\n<\\\/ul>\\n<\\\/li>\\n<\\\/ul>\\n\n\n<p><span style=\\\"font-weight: 400;\\\">For URL\\u2019s<\\\/span><\\\/p>\\n\n\n<ul>\\n\n\n<li style=\\\"list-style-type: none;\\\">\\n\n\n<ul>\\n\n\n<li style=\\\"font-weight: 400;\\\"><span style=\\\"font-weight: 400;\\\">If a URL filtering server is used, ensure that it is appropriately defined in the firewall software. (If the filtering server is external to the (<\\\/span><b>Organization<\\\/b><span style=\\\"font-weight: 400;\\\">) ensure that it is a trusted source).<\\\/span><\\\/li>\\n\n\n<li style=\\\"font-weight: 400;\\\"><span style=\\\"font-weight: 400;\\\">If filtering on MAC addresses is allowed, review the filters to ensure that it is restricted to the appropriate MAC\\u2019s at (<\\\/span><b>Organization<\\\/b><span style=\\\"font-weight: 400;\\\">).<\\\/span><\\\/li>\\n<\\\/ul>\\n<\\\/li>\\n<\\\/ul>\\n\n\n<ol>\\n\n\n<li style=\\\"font-weight: 400;\\\"><span style=\\\"font-weight: 400;\\\">Logging<\\\/span><\\\/li>\\n<\\\/ol>\\n\n\n<ul>\\n\n\n<li style=\\\"list-style-type: none;\\\">\\n\n\n<ul>\\n\n\n<li style=\\\"font-weight: 400;\\\"><span style=\\\"font-weight: 400;\\\">Ensure that logging is enabled and that the logs are reviewed to identify any potential patterns that could indicate an attack.<\\\/span><\\\/li>\\n\n\n<li style=\\\"font-weight: 400;\\\"><span style=\\\"font-weight: 400;\\\">Network Firewall administration logs (administrative activities) and event logs (traffic activity) should:<\\\/span><\\\/li>\\n<\\\/ul>\\n<\\\/li>\\n<\\\/ul>\\n\n\n<ul>\\n\n\n<li style=\\\"list-style-type: none;\\\">\\n\n\n<ul>\\n\n\n<li style=\\\"font-weight: 400;\\\"><span style=\\\"font-weight: 400;\\\">Be written to alternate storage (not on the same device)\\u00a0<\\\/span><\\\/li>\\n\n\n<li style=\\\"font-weight: 400;\\\"><span style=\\\"font-weight: 400;\\\">Be reviewed at least daily, with logs retained for ninety (90) days.\\u00a0<\\\/span><\\\/li>\\n<\\\/ul>\\n<\\\/li>\\n<\\\/ul>\\n\n\n<ol>\\n\n\n<li style=\\\"font-weight: 400;\\\"><span style=\\\"font-weight: 400;\\\">Patches and updates<\\\/span><\\\/li>\\n<\\\/ol>\\n\n\n<ul>\\n\n\n<li style=\\\"list-style-type: none;\\\">\\n\n\n<ul>\\n\n\n<li style=\\\"font-weight: 400;\\\"><span style=\\\"font-weight: 400;\\\">Ensure that the latest patches and updates relating to your firewall product is tested and installed.<\\\/span><\\\/li>\\n\n\n<li style=\\\"font-weight: 400;\\\"><span style=\\\"font-weight: 400;\\\">If patches and updates are automatically downloaded from the vendors\\u2019 websites, ensure that the update is received from a trusted site.<\\\/span><\\\/li>\\n\n\n<li style=\\\"font-weight: 400;\\\"><span style=\\\"font-weight: 400;\\\">In the event that patches and updates are e-mailed to the systems administrator ensure that digital signatures are used to verify the vendor and ensure that the information has not been modified en-route.<\\\/span><\\\/li>\\n<\\\/ul>\\n<\\\/li>\\n<\\\/ul>\\n\n\n<ol>\\n\n\n<li style=\\\"font-weight: 400;\\\"><span style=\\\"font-weight: 400;\\\">Vulnerability assessments\\\/ Testing<\\\/span><\\\/li>\\n<\\\/ol>\\n\n\n<ul>\\n\n\n<li style=\\\"list-style-type: none;\\\">\\n\n\n<ul>\\n\n\n<li style=\\\"font-weight: 400;\\\"><span style=\\\"font-weight: 400;\\\">Ascertain if there is a procedure to test for open ports using (NMAP) and whether unnecessary ports are closed.<\\\/span><\\\/li>\\n\n\n<li style=\\\"font-weight: 400;\\\"><span style=\\\"font-weight: 400;\\\">Ensure that there is a procedure to test the rulesets when established or changed so as not to create a denial of service on the (<\\\/span><b>organization<\\\/b><span style=\\\"font-weight: 400;\\\">) or allow any weaknesses to continue undetected.<\\\/span><\\\/li>\\n<\\\/ul>\\n<\\\/li>\\n<\\\/ul>\\n\n\n<ol>\\n\n\n<li style=\\\"list-style-type: none;\\\">\\n\n\n<ol>\\n\n\n<li style=\\\"font-weight: 400;\\\"><span style=\\\"font-weight: 400;\\\">Compliance with security policy<\\\/span><\\\/li>\\n<\\\/ol>\\n<\\\/li>\\n<\\\/ol>\\n\n\n<ul>\\n\n\n<li style=\\\"list-style-type: none;\\\">\\n\n\n<ul>\\n\n\n<li style=\\\"font-weight: 400;\\\"><span style=\\\"font-weight: 400;\\\">Ensure that the ruleset complies with the (<\\\/span><b>organization<\\\/b><span style=\\\"font-weight: 400;\\\">) security policy.<\\\/span><\\\/li>\\n\n\n<li><span style=\\\"font-weight: 400;\\\">\\u00a0Ensure that the following spoofed, private (RFC 1918) and illegal addresses are blocked:<\\\/span><\\\/li>\\n<\\\/ul>\\n<\\\/li>\\n\n\n<li><b>Private (RFC 1918) addresses<\\\/b><\\\/li>\\n<\\\/ul>\\n\n\n<p style=\\\"padding-left: 40px;\\\"><span style=\\\"font-weight: 400;\\\">10.0.0.0 \\u2013 10.255.255.255<\\\/span><\\\/p>\\n\n\n<p style=\\\"padding-left: 40px;\\\"><span style=\\\"font-weight: 400;\\\">172.16.0.0 \\u2013 172.31.255.255<\\\/span><\\\/p>\\n\n\n<p style=\\\"padding-left: 40px;\\\"><span style=\\\"font-weight: 400;\\\">192.168.0.0 - 192.168.255.255<\\\/span><\\\/p>\\n\n\n<ul>\\n\n\n<li><b>Reserved addresses<\\\/b><\\\/li>\\n<\\\/ul>\\n\n\n<p style=\\\"padding-left: 40px;\\\"><span style=\\\"font-weight: 400;\\\">240.0.0.0<\\\/span><\\\/p>\\n\n\n<ul>\\n\n\n<li><b>Illegal addresses<\\\/b>\\n\n\n<ul>\\n\n\n<li style=\\\"list-style-type: none;\\\">\\n\n\n<ul>\\n\n\n<li><b><\\\/b>\\n\n\n<p><span style=\\\"font-weight: 400;\\\">0.0.0.0<\\\/span><\\\/p>\\n\n\n<ul>\\n\n\n<li style=\\\"font-weight: 400;\\\"><span style=\\\"font-weight: 400;\\\">UDP echo<\\\/span><\\\/li>\\n\n\n<li style=\\\"font-weight: 400;\\\"><span style=\\\"font-weight: 400;\\\">ICMP broadcast (RFC 2644)<\\\/span><\\\/li>\\n<\\\/ul>\\n<\\\/li>\\n<\\\/ul>\\n<\\\/li>\\n<\\\/ul>\\n<\\\/li>\\n<\\\/ul>\\n\n\n<ol>\\n\n\n<li style=\\\"font-weight: 400;\\\"><span style=\\\"font-weight: 400;\\\">Remote access<\\\/span><\\\/li>\\n<\\\/ol>\\n\n\n<ul>\\n\n\n<li style=\\\"font-weight: 400;\\\"><span style=\\\"font-weight: 400;\\\">If remote access is to be used, ensure that the SSH protocol (port 22) is used instead of Telnet.<\\\/span><\\\/li>\\n<\\\/ul>\\n\n\n<ol>\\n\n\n<li style=\\\"font-weight: 400;\\\"><span style=\\\"font-weight: 400;\\\">\\u00a0File Transfers<\\\/span><\\\/li>\\n<\\\/ol>\\n\n\n<ul>\\n\n\n<li style=\\\"font-weight: 400;\\\"><span style=\\\"font-weight: 400;\\\">If FTP is a requirement, ensure that the server, which supports FTP, is placed in a different subnet than the internal protected network.<\\\/span><\\\/li>\\n<\\\/ul>\\n\n\n<ol>\\n\n\n<li style=\\\"font-weight: 400;\\\"><span style=\\\"font-weight: 400;\\\">Mail Traffic<\\\/span><\\\/li>\\n<\\\/ol>\\n\n\n<ul>\\n\n\n<li style=\\\"font-weight: 400;\\\"><span style=\\\"font-weight: 400;\\\">Ascertain which protocol is used for mail and ensure that there is a rule to block incoming mail traffic except to internal mail.<\\\/span><\\\/li>\\n<\\\/ul>\\n\n\n<ol>\\n\n\n<li style=\\\"font-weight: 400;\\\"><span style=\\\"font-weight: 400;\\\">Block Unwanted ICMP Traffic (ICMP 8, 11, 3)<\\\/span><\\\/li>\\n<\\\/ol>\\n\n\n<ul>\\n\n\n<li style=\\\"font-weight: 400;\\\"><span style=\\\"font-weight: 400;\\\">Ensure that there is a rule blocking ICMP echo requests and replies.<\\\/span><\\\/li>\\n\n\n<li style=\\\"font-weight: 400;\\\"><span style=\\\"font-weight: 400;\\\">Ensure that there is a rule blocking outgoing time exceeded and unreachable messages.<\\\/span><\\\/li>\\n<\\\/ul>\\n\n\n<ol>\\n\n\n<li style=\\\"font-weight: 400;\\\"><span style=\\\"font-weight: 400;\\\">Critical servers<\\\/span><\\\/li>\\n<\\\/ol>\\n\n\n<ul>\\n\n\n<li style=\\\"font-weight: 400;\\\"><span style=\\\"font-weight: 400;\\\">Ensure that there is a deny rule for traffic destined to critical internal addresses from external sources. This rule is based on the organizational requirements, since some <\\\/span><b>(organizations)<\\\/b><span style=\\\"font-weight: 400;\\\"> may allow traffic via a web application to be routed via a DMZ.<\\\/span><\\\/li>\\n<\\\/ul>\\n\n\n<ol>\\n\n\n<li style=\\\"font-weight: 400;\\\"><span style=\\\"font-weight: 400;\\\">Personal firewalls<\\\/span><\\\/li>\\n<\\\/ol>\\n\n\n<ul>\\n\n\n<li style=\\\"font-weight: 400;\\\"><span style=\\\"font-weight: 400;\\\">Ensure that laptop users are given appropriate training regarding the threats, types of elements blocked by the firewall and guidelines for operation of the personal firewall. This element is essential, since often times personal firewalls rely on user prompt to respond to attacks e.g. whether to accept\\\/deny a request from a specific address.<\\\/span><\\\/li>\\n\n\n<li style=\\\"font-weight: 400;\\\"><span style=\\\"font-weight: 400;\\\">Review the security settings of the personal firewall to ensure that it restricts access to specific ports, protects against known attacks, and that there is adequate logging and user alerts in the event of an intrusion.<\\\/span><\\\/li>\\n\n\n<li style=\\\"font-weight: 400;\\\"><span style=\\\"font-weight: 400;\\\">Ensure that there is a procedure to update the software for any new attacks that become known.<\\\/span><\\\/li>\\n<\\\/ul>\\n\n\n<p><span style=\\\"font-weight: 400;\\\">Alternatively, most tools provide the option of transferring automatic updates via the internet. In such instances ensure that updates are received from trusted sites.<\\\/span><\\\/p>\\n\n\n<ol>\\n\n\n<li style=\\\"font-weight: 400;\\\"><span style=\\\"font-weight: 400;\\\">Distributed firewalls<\\\/span><\\\/li>\\n<\\\/ol>\\n\n\n<ul>\\n\n\n<li style=\\\"font-weight: 400;\\\"><span style=\\\"font-weight: 400;\\\">Ensure that the security policy is consistently distributed to all hosts especially when there are changes to the policy.<\\\/span><\\\/li>\\n\n\n<li style=\\\"font-weight: 400;\\\"><span style=\\\"font-weight: 400;\\\">Ensure that there are adequate controls to ensure the integrity of the policy during transfer, e.g. IPsec to encrypt the policy when in transfer.<\\\/span><\\\/li>\\n\n\n<li style=\\\"font-weight: 400;\\\"><span style=\\\"font-weight: 400;\\\">Ensure that there are adequate controls to authenticate the appropriate host.<\\\/span><\\\/li>\\n<\\\/ul>\\n\n\n<p><span style=\\\"font-weight: 400;\\\">Again IPsec can be used for authentication with cryptographic certificates.<\\\/span><\\\/p>\\n\n\n<ol>\\n\n\n<li style=\\\"font-weight: 400;\\\"><span style=\\\"font-weight: 400;\\\">Continued availability of Firewalls<\\\/span><\\\/li>\\n<\\\/ol>\\n\n\n<ul>\\n\n\n<li style=\\\"font-weight: 400;\\\"><span style=\\\"font-weight: 400;\\\">Ensure that there is a hot standby for the primary firewall<\\\/span><\\\/li>\\n<\\\/ul>\\n\n\n<ol>\\n\n\n<li style=\\\"font-weight: 400;\\\"><span style=\\\"font-weight: 400;\\\">Network configurations and changes must be documented regularly to understand its structure. Network documentation should include:\\u00a0<\\\/span><\\\/li>\\n<\\\/ol>\\n\n\n<ul>\\n\n\n<li style=\\\"font-weight: 400;\\\"><span style=\\\"font-weight: 400;\\\">\\u00a0Network diagram\\u00a0<\\\/span><\\\/li>\\n\n\n<li style=\\\"font-weight: 400;\\\"><span style=\\\"font-weight: 400;\\\">\\u00a0System configurations\\u00a0<\\\/span><\\\/li>\\n\n\n<li style=\\\"font-weight: 400;\\\"><span style=\\\"font-weight: 400;\\\">\\u00a0Firewall rule set\\u00a0<\\\/span><\\\/li>\\n\n\n<li style=\\\"font-weight: 400;\\\"><span style=\\\"font-weight: 400;\\\">\\u00a0IP Addresses<\\\/span><\\\/li>\\n\n\n<li style=\\\"font-weight: 400;\\\"><span style=\\\"font-weight: 400;\\\">Access Control Lists<\\\/span><\\\/li>\\n<\\\/ul>\"}}]},{\"type\":\"html\",\"props\":{\"id\":\"irc_footer\",\"content\":\"<base>\"},\"name\":\"Stop Sidebar element\"}]},{\"type\":\"column\",\"props\":{\"image_position\":\"center-center\",\"media_overlay_gradient\":\"\",\"vertical_align\":\"\",\"style\":\"\",\"text_color\":\"\",\"padding\":\"\"},\"children\":[{\"type\":\"wordpress_area\",\"props\":{\"layout\":\"stack\",\"breakpoint\":\"m\",\"content\":\"builder-1\",\"column_gap\":\"\",\"row_gap\":\"\",\"position\":\"\",\"position_z_index\":\"\",\"margin\":\"\",\"maxwidth\":\"\",\"maxwidth_breakpoint\":\"\",\"block_align\":\"\",\"block_align_breakpoint\":\"\",\"block_align_fallback\":\"\",\"text_align\":\"\",\"text_align_breakpoint\":\"\",\"text_align_fallback\":\"\",\"animation\":\"\",\"visibility\":\"\"}}]}]}]}],\"version\":\"1.22.8\",\"props\":[]} --><\/p>\n","protected":false},"excerpt":{"rendered":"<p>You can National Information Security &#038; Safety Authority policies as pdf by clicking on this link download Router and Switch Security Policy Introduction Routers and smart switches provide important security functions within a network. Configured correctly, they are one of several hardware and software devices available that help manage and protect a private network from [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":3574,"parent":3668,"menu_order":0,"comment_status":"closed","ping_status":"closed","template":"","meta":{"_acf_changed":false,"footnotes":""},"class_list":["post-3605","page","type-page","status-publish","has-post-thumbnail","hentry"],"acf":[],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v28.3 - https:\/\/yoast.com\/product\/yoast-seo-wordpress\/ -->\n<title>Network Security Policy - \u0627\u0644\u0647\u064a\u0626\u0629 \u0627\u0644\u0648\u0637\u0646\u064a\u0629 \u0644\u0623\u0645\u0646 \u0648\u0633\u0644\u0627\u0645\u0629 \u0627\u0644\u0645\u0639\u0644\u0648\u0645\u0627\u062a<\/title>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/nissa.gov.ly\/en\/main-services\/network-security-policies\/\" \/>\n<meta property=\"og:locale\" content=\"ar_AR\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"Network Security Policy - \u0627\u0644\u0647\u064a\u0626\u0629 \u0627\u0644\u0648\u0637\u0646\u064a\u0629 \u0644\u0623\u0645\u0646 \u0648\u0633\u0644\u0627\u0645\u0629 \u0627\u0644\u0645\u0639\u0644\u0648\u0645\u0627\u062a\" \/>\n<meta property=\"og:description\" content=\"You can National Information Security &#038; Safety Authority policies as pdf by clicking on this link download Router and Switch Security Policy Introduction Routers and smart switches provide important security functions within a network. Configured correctly, they are one of several hardware and software devices available that help manage and protect a private network from [&hellip;]\" \/>\n<meta property=\"og:url\" content=\"https:\/\/nissa.gov.ly\/en\/main-services\/network-security-policies\/\" \/>\n<meta property=\"og:site_name\" content=\"\u0627\u0644\u0647\u064a\u0626\u0629 \u0627\u0644\u0648\u0637\u0646\u064a\u0629 \u0644\u0623\u0645\u0646 \u0648\u0633\u0644\u0627\u0645\u0629 \u0627\u0644\u0645\u0639\u0644\u0648\u0645\u0627\u062a\" \/>\n<meta property=\"article:modified_time\" content=\"2020-04-19T20:40:17+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/nissa.gov.ly\/gavedug\/placeholder.png\" \/>\n\t<meta property=\"og:image:width\" content=\"1153\" \/>\n\t<meta property=\"og:image:height\" content=\"645\" \/>\n\t<meta property=\"og:image:type\" content=\"image\/png\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:label1\" content=\"\u0648\u0642\u062a \u0627\u0644\u0642\u0631\u0627\u0621\u0629 \u0627\u0644\u0645\u064f\u0642\u062f\u0651\u0631\" \/>\n\t<meta name=\"twitter:data1\" content=\"14 \u062f\u0642\u064a\u0642\u0629\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\\\/\\\/schema.org\",\"@graph\":[{\"@type\":\"WebPage\",\"@id\":\"https:\\\/\\\/nissa.gov.ly\\\/en\\\/main-services\\\/network-security-policies\\\/\",\"url\":\"https:\\\/\\\/nissa.gov.ly\\\/en\\\/main-services\\\/network-security-policies\\\/\",\"name\":\"Network Security Policy - \u0627\u0644\u0647\u064a\u0626\u0629 \u0627\u0644\u0648\u0637\u0646\u064a\u0629 \u0644\u0623\u0645\u0646 \u0648\u0633\u0644\u0627\u0645\u0629 \u0627\u0644\u0645\u0639\u0644\u0648\u0645\u0627\u062a\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/nissa.gov.ly\\\/#website\"},\"primaryImageOfPage\":{\"@id\":\"https:\\\/\\\/nissa.gov.ly\\\/en\\\/main-services\\\/network-security-policies\\\/#primaryimage\"},\"image\":{\"@id\":\"https:\\\/\\\/nissa.gov.ly\\\/en\\\/main-services\\\/network-security-policies\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/nissa.gov.ly\\\/wp-content\\\/uploads\\\/placeholder.png\",\"datePublished\":\"2020-01-23T12:31:44+00:00\",\"dateModified\":\"2020-04-19T20:40:17+00:00\",\"breadcrumb\":{\"@id\":\"https:\\\/\\\/nissa.gov.ly\\\/en\\\/main-services\\\/network-security-policies\\\/#breadcrumb\"},\"inLanguage\":\"ar\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\\\/\\\/nissa.gov.ly\\\/en\\\/main-services\\\/network-security-policies\\\/\"]}]},{\"@type\":\"ImageObject\",\"inLanguage\":\"ar\",\"@id\":\"https:\\\/\\\/nissa.gov.ly\\\/en\\\/main-services\\\/network-security-policies\\\/#primaryimage\",\"url\":\"https:\\\/\\\/nissa.gov.ly\\\/wp-content\\\/uploads\\\/placeholder.png\",\"contentUrl\":\"https:\\\/\\\/nissa.gov.ly\\\/wp-content\\\/uploads\\\/placeholder.png\",\"width\":1153,\"height\":645},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\\\/\\\/nissa.gov.ly\\\/en\\\/main-services\\\/network-security-policies\\\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\\\/\\\/nissa.gov.ly\\\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"Main services\",\"item\":\"https:\\\/\\\/nissa.gov.ly\\\/en\\\/main-services\\\/\"},{\"@type\":\"ListItem\",\"position\":3,\"name\":\"Network Security Policy\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\\\/\\\/nissa.gov.ly\\\/#website\",\"url\":\"https:\\\/\\\/nissa.gov.ly\\\/\",\"name\":\"\u0627\u0644\u0647\u064a\u0626\u0629 \u0627\u0644\u0648\u0637\u0646\u064a\u0629 \u0644\u0623\u0645\u0646 \u0648\u0633\u0644\u0627\u0645\u0629 \u0627\u0644\u0645\u0639\u0644\u0648\u0645\u0627\u062a\",\"description\":\"\",\"publisher\":{\"@id\":\"https:\\\/\\\/nissa.gov.ly\\\/#organization\"},\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\\\/\\\/nissa.gov.ly\\\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"ar\"},{\"@type\":\"Organization\",\"@id\":\"https:\\\/\\\/nissa.gov.ly\\\/#organization\",\"name\":\"\u0627\u0644\u0647\u064a\u0626\u0629 \u0627\u0644\u0648\u0637\u0646\u064a\u0629 \u0644\u0623\u0645\u0646 \u0648\u0633\u0644\u0627\u0645\u0629 \u0627\u0644\u0645\u0639\u0644\u0648\u0645\u0627\u062a\",\"url\":\"https:\\\/\\\/nissa.gov.ly\\\/\",\"logo\":{\"@type\":\"ImageObject\",\"inLanguage\":\"ar\",\"@id\":\"https:\\\/\\\/nissa.gov.ly\\\/#\\\/schema\\\/logo\\\/image\\\/\",\"url\":\"https:\\\/\\\/nissa.gov.ly\\\/wp-content\\\/uploads\\\/apple-touch-icon.png\",\"contentUrl\":\"https:\\\/\\\/nissa.gov.ly\\\/wp-content\\\/uploads\\\/apple-touch-icon.png\",\"width\":180,\"height\":180,\"caption\":\"\u0627\u0644\u0647\u064a\u0626\u0629 \u0627\u0644\u0648\u0637\u0646\u064a\u0629 \u0644\u0623\u0645\u0646 \u0648\u0633\u0644\u0627\u0645\u0629 \u0627\u0644\u0645\u0639\u0644\u0648\u0645\u0627\u062a\"},\"image\":{\"@id\":\"https:\\\/\\\/nissa.gov.ly\\\/#\\\/schema\\\/logo\\\/image\\\/\"}}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"Network Security Policy - \u0627\u0644\u0647\u064a\u0626\u0629 \u0627\u0644\u0648\u0637\u0646\u064a\u0629 \u0644\u0623\u0645\u0646 \u0648\u0633\u0644\u0627\u0645\u0629 \u0627\u0644\u0645\u0639\u0644\u0648\u0645\u0627\u062a","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/nissa.gov.ly\/en\/main-services\/network-security-policies\/","og_locale":"ar_AR","og_type":"article","og_title":"Network Security Policy - \u0627\u0644\u0647\u064a\u0626\u0629 \u0627\u0644\u0648\u0637\u0646\u064a\u0629 \u0644\u0623\u0645\u0646 \u0648\u0633\u0644\u0627\u0645\u0629 \u0627\u0644\u0645\u0639\u0644\u0648\u0645\u0627\u062a","og_description":"You can National Information Security &#038; Safety Authority policies as pdf by clicking on this link download Router and Switch Security Policy Introduction Routers and smart switches provide important security functions within a network. Configured correctly, they are one of several hardware and software devices available that help manage and protect a private network from [&hellip;]","og_url":"https:\/\/nissa.gov.ly\/en\/main-services\/network-security-policies\/","og_site_name":"\u0627\u0644\u0647\u064a\u0626\u0629 \u0627\u0644\u0648\u0637\u0646\u064a\u0629 \u0644\u0623\u0645\u0646 \u0648\u0633\u0644\u0627\u0645\u0629 \u0627\u0644\u0645\u0639\u0644\u0648\u0645\u0627\u062a","article_modified_time":"2020-04-19T20:40:17+00:00","og_image":[{"width":1153,"height":645,"url":"https:\/\/nissa.gov.ly\/gavedug\/placeholder.png","type":"image\/png"}],"twitter_card":"summary_large_image","twitter_misc":{"\u0648\u0642\u062a \u0627\u0644\u0642\u0631\u0627\u0621\u0629 \u0627\u0644\u0645\u064f\u0642\u062f\u0651\u0631":"14 \u062f\u0642\u064a\u0642\u0629"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"WebPage","@id":"https:\/\/nissa.gov.ly\/en\/main-services\/network-security-policies\/","url":"https:\/\/nissa.gov.ly\/en\/main-services\/network-security-policies\/","name":"Network Security Policy - \u0627\u0644\u0647\u064a\u0626\u0629 \u0627\u0644\u0648\u0637\u0646\u064a\u0629 \u0644\u0623\u0645\u0646 \u0648\u0633\u0644\u0627\u0645\u0629 \u0627\u0644\u0645\u0639\u0644\u0648\u0645\u0627\u062a","isPartOf":{"@id":"https:\/\/nissa.gov.ly\/#website"},"primaryImageOfPage":{"@id":"https:\/\/nissa.gov.ly\/en\/main-services\/network-security-policies\/#primaryimage"},"image":{"@id":"https:\/\/nissa.gov.ly\/en\/main-services\/network-security-policies\/#primaryimage"},"thumbnailUrl":"https:\/\/nissa.gov.ly\/gavedug\/placeholder.png","datePublished":"2020-01-23T12:31:44+00:00","dateModified":"2020-04-19T20:40:17+00:00","breadcrumb":{"@id":"https:\/\/nissa.gov.ly\/en\/main-services\/network-security-policies\/#breadcrumb"},"inLanguage":"ar","potentialAction":[{"@type":"ReadAction","target":["https:\/\/nissa.gov.ly\/en\/main-services\/network-security-policies\/"]}]},{"@type":"ImageObject","inLanguage":"ar","@id":"https:\/\/nissa.gov.ly\/en\/main-services\/network-security-policies\/#primaryimage","url":"https:\/\/nissa.gov.ly\/gavedug\/placeholder.png","contentUrl":"https:\/\/nissa.gov.ly\/gavedug\/placeholder.png","width":1153,"height":645},{"@type":"BreadcrumbList","@id":"https:\/\/nissa.gov.ly\/en\/main-services\/network-security-policies\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/nissa.gov.ly\/"},{"@type":"ListItem","position":2,"name":"Main services","item":"https:\/\/nissa.gov.ly\/en\/main-services\/"},{"@type":"ListItem","position":3,"name":"Network Security Policy"}]},{"@type":"WebSite","@id":"https:\/\/nissa.gov.ly\/#website","url":"https:\/\/nissa.gov.ly\/","name":"\u0627\u0644\u0647\u064a\u0626\u0629 \u0627\u0644\u0648\u0637\u0646\u064a\u0629 \u0644\u0623\u0645\u0646 \u0648\u0633\u0644\u0627\u0645\u0629 \u0627\u0644\u0645\u0639\u0644\u0648\u0645\u0627\u062a","description":"","publisher":{"@id":"https:\/\/nissa.gov.ly\/#organization"},"potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/nissa.gov.ly\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"ar"},{"@type":"Organization","@id":"https:\/\/nissa.gov.ly\/#organization","name":"\u0627\u0644\u0647\u064a\u0626\u0629 \u0627\u0644\u0648\u0637\u0646\u064a\u0629 \u0644\u0623\u0645\u0646 \u0648\u0633\u0644\u0627\u0645\u0629 \u0627\u0644\u0645\u0639\u0644\u0648\u0645\u0627\u062a","url":"https:\/\/nissa.gov.ly\/","logo":{"@type":"ImageObject","inLanguage":"ar","@id":"https:\/\/nissa.gov.ly\/#\/schema\/logo\/image\/","url":"https:\/\/nissa.gov.ly\/gavedug\/apple-touch-icon.png","contentUrl":"https:\/\/nissa.gov.ly\/gavedug\/apple-touch-icon.png","width":180,"height":180,"caption":"\u0627\u0644\u0647\u064a\u0626\u0629 \u0627\u0644\u0648\u0637\u0646\u064a\u0629 \u0644\u0623\u0645\u0646 \u0648\u0633\u0644\u0627\u0645\u0629 \u0627\u0644\u0645\u0639\u0644\u0648\u0645\u0627\u062a"},"image":{"@id":"https:\/\/nissa.gov.ly\/#\/schema\/logo\/image\/"}}]}},"_links":{"self":[{"href":"https:\/\/nissa.gov.ly\/batisur\/wp\/v2\/pages\/3605","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/nissa.gov.ly\/batisur\/wp\/v2\/pages"}],"about":[{"href":"https:\/\/nissa.gov.ly\/batisur\/wp\/v2\/types\/page"}],"author":[{"embeddable":true,"href":"https:\/\/nissa.gov.ly\/batisur\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/nissa.gov.ly\/batisur\/wp\/v2\/comments?post=3605"}],"version-history":[{"count":0,"href":"https:\/\/nissa.gov.ly\/batisur\/wp\/v2\/pages\/3605\/revisions"}],"up":[{"embeddable":true,"href":"https:\/\/nissa.gov.ly\/batisur\/wp\/v2\/pages\/3668"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/nissa.gov.ly\/batisur\/wp\/v2\/media\/3574"}],"wp:attachment":[{"href":"https:\/\/nissa.gov.ly\/batisur\/wp\/v2\/media?parent=3605"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}