These are rules signed by a certificate authority that is valid, and so they are on the list of the allowed apps into the local network and they do not prompt firewall administrator to allow. The rules in the case that belong to this category are rules 4 and 8. These rules usually allow the access to the web server and the SMTP respectively of the source traffic from trusted sites. The allowed traffic uses the same port.
Outgoing allowed rules
These rules have the same sort of communication in that they allow then traffic from the local network to the outside the network. The rule belonging to this class is rule 3 and rule 6 that allow the outgoing traffic from all local network computers to access the outside websites. Allowance for the outgoing traffic takes place when the outside source is a trusted one and thus there is no need to restrict the access (Spitzner, 2000). These rules belong to the same sort of communication.
Incoming denied rules
These types of rules entail the blocking of entrusted communications from the outside sources to the local network. Then rule in our case study that belongs to this category of communications is rule 1.
Outgoing denied rules
The outgoing denied rules restrict the access of the local network devices from accessing any website outside the local network (Mitrou, 2004). The rule belonging to this type of communication is rule 2 in our case. It blocks any access to the Internet via the S-HTTP.
- Rules too down the list
The rules that are too down the list and need to move are rules 5, 7 and 8. That is because the rules that are most used should be at the top of the rule base (Anderson, 2008). Rule 5 is a commonly used because it entails the network making inquiries to the FNS server, something that takes place more often. Rule 7 also entails the communication via the email, something that occurs more often than not in any organization. On the other hand, Rule 8 is also a type of rule used more often in any organization. That is because it includes the access of the computers to the SMTP server, and this is something that takes place always as the network management is taking place every time.
- Rules that give the firewall more work than unnecessary
The rules 5 and 6 give the firewall more work than is necessary because of involving unnecessary tracking that is not a must for it to take place. Rule 5 falls in the category of allowed communication to the DNS using the UDP protocol and there is no need to for the firewall to have tracking of the same. On the other hand, Rule 6 pertains to the communication of the trusted outside sources from the internal network and thus there is no need for the firewall to keep on tracking. The tracking of these activities and yet they are allowed puts much work on the firewall that otherwise would be unnecessary. That is because the firewall needs to perform the tracking of the type of communications that belong to the disallowed category (Apple Inc. 2015). That is because that kind of communications is the ones that may prove to be a threat to the security of the local network resources.
References
Anderson, B. (2008). Check point firewalls –rulebase cleanup and performance tuning.
Apple Inc. (2015). OS X: About the application firewall.
Mitrou, N. (2004). Networking 2004: Networking technologies, services, and protocols : performance of computer and communication networks : mobile and wireless communications. Third International IFIP-TC6 Networking Conference, Athens, Greece.
Spitzner, L. (2000). Building your firewall rulebase.
Rule base table
| Rule | Source IP | Destination IP | Protocol | Action | Track | Comments |
| 1 | 210.100.101.0 to
210.100.101.255 |
210.100.101.0 to
210.100.101.255 |
Any | Deny | log | Protects against any spoofing attacks |
| 2 | Any | 210.100.101.2 | HTTP | Allow | Log | Allowing computers access to the HTTP service |
| 3 | Any | 210.100.101.4 | TCP | Allow | None | Allow computers have access to SMTP |
| 4 | 210.100.101.0 to
210.100.101.255 |
210.100.101.3 | UDP | Allow | Log | Network access to the DNS service |
| 5 | 210.100.101.0 to
210.100.101.255 |
Any | HTTP, S-HTTP | Allow | None | Network access to web servers |
| 6 | Any | Any | Any | Drop | Log | Cleanup rule |
Carolyn Morgan is the author of this paper. A senior editor at MeldaResearch.Com in legitimate essay writing service. If you need a similar paper you can place your order from .

