I have 2 asg appliances (a 220 and a 110) installed by consultants connecting to the Internet and to each other via site to site vpn. I'm not sure why some of the stuff they put in is there.
The branch office, (the 110) has just 1 rule, 1 masq, no dnat and the site2site vpn has auto packet filter set.
The masq says any to external. Shouldn't that be internal to external?
The PF rule says internal any any. Isn't that the default, that the internal network can initiate any connection? Is that rule necessary? Should it be more restrictive?
On the main office (the 220, where there are web servers, databases, etc) there is a PF rule that says any any https. Why do I need this. I can webadmin my remote asg whether this rule is on or off.
Some real life samples of some best practices rule sets would be really helpful.
This thread was automatically locked due to age.