
318 ◾ Network Attacks and Defenses: A Hands-on Approach
8.4.5.6 Step 6: Implement the Security
Policies on Border Router FW
The following security policies are implemented on router FW:
1. Security policy: Deny RFC 1918 addresses sourced from
outside and log. Use the extended access control list (INF)
to match the source addresses that belong to the private
addresses defined by RFC 1918.
2. Security policy: Implement RFC 2827 and log using ingress
traffic filtering. To prevent a DoS attack that employs
spoofed IP source addresses, a security measure must
be implemented to block packets that claim to have IP
source addresses similar to the inte ...