Firewall Policies
Hello to all,
I would like to know you're best practices and approaches on configuring Firewall Policies to be as restricted as possible.
I want to restrict access as much as I can.
- Examples would be to allow only certain Services for certain Servers (for DNS servers only port 53 etc), For Pirnters only SMB and so on.
- From Clients to Servers also only needed services for specific Servers (AD, Print Servers, File Servers)
- IT to have adminsitration rights for all servers
- Restricted for others that don't need anything else that services
I think you get the point what I want to achieve.
We already have something like that for our branch office, but I want to see if there are some better recommendations.
And also I don't have zoning concept. Don't know if granular restrictions can be a lot of work with zoning since I'm going to have few VLANs etc.
This is an example of our branch office:
Like this our Firewall Rules are getting larger and more difficult to manage.
over 100 rules
Best Regards,
Nemanja
