SunScreen 3.2 Administrator's Overview

Example of a Rule Configuration

XYZ Company wants to set up SunScreen rules to implement the following security policy:

  1. Allow telnet traffic from A (an individual host) to B (any host on a specified network).

  2. Deny mail traffic between A and B; log attempts.

  3. Deny all other telnet traffic and send NET_UNREACHABLE ICMP rejection messages for rejected traffic.

  4. Discard all other packets.

The table below illustrates the SunScreen rules that the XYZ Company would set up to implement this security policy. Note that the default action for services not expressly mentioned in a rule would be specified as DENY.

Table 3-1 Sample Rules Table

Service 

From 

To 

Rule Type 

Log 

SNMP 

ICMP 

telnet 

Allow 

NONE 

NONE 

NONE 

mail 

Deny 

SUMMARY 

NONE 

NONE 

mail 

Deny 

SUMMARY 

NONE 

NONE 

telnet 

Deny 

NONE 

NONE 

NET_UNREACHABLE