System>Administration
- Password must be changed every 90 days
- Bar repeated password changes for 4 changes
- Enforce password complexity: Require alphabetic, numeric and symbolic characters
- Apply the above password constraints for: all user categories
- Enable administrator/user lockout
- Failed Login attempts per minute before lockout: 7
- Enable inter-administrator messaging
- Inter-administrator Messaging polling interval (seconds): 10
Network>Interfaces
- Any interface allowing HTTP management is replaced with HTTPS Management
- Any setting to 'Add rule to enable redirect from HTTP to HTTPS' is disabled
- Ping Management is disabled on all interfaces
Network>Zones
- Intrusion Prevention is enabled on all applicable default Zones
- Gateway Anti-Virus protection is enabled on all applicable default Zones
- Anti-Spyware protection is enabled on all applicable default Zones
- App Rules is enabled on all applicable default Zones
- SSL Control is enabled on all default Zones
Network>DNS
- Enable DNS Rebinding protection
- DNS Rebinding Action: Log Attack & Drop DNS Reply
Firewall>Access Rules
- Any Firewall policy with an Action of Deny, the Action is changed Discard
- Source IP Address connection limiting with a threshold of 128 connections is enabled for all firewall policies
Firewall>App Rules
- If licensed, the Enable App Rules setting is turned on
Firewall Settings>Advanced
- Turn on Enable Stealth Mode
- Turn on Randomize IP ID
- Turn off Decrement IP TTL for forwarded traffic
- Connections are set to: DPI Connections (DPI services enabled with additional performance optimizations)
- Turn on Enable IP header checksum enforcement
- Turn on Enable UDP checksum enforcement
Firewall Settings>Flood Protection
- Turn on Enforce strict TCP compliance with RFC 793 and RFC 1122
- Turn on Enable TCP handshake enforcement
- Turn on Enable TCP checksum enforcement
- Turn on Enable TCP handshake timeout
- SYN Flood Protection Mode: Always proxy WAN client connections
Firewall Settings>SSL Control
- Turn on Enable SSL Control
- Set Action to: Block connection and log the event
- For Configuration, enable all categories
VPN>Advanced
- Turn on Enable IKE Dead Peer Detection
- Turn on Enable Dead Peer Detection for Idle VPN sessions
- Turn on Enable Fragmented Packet Handling
- Turn on Ignore DF (Dont Fragment) Bit
- Turn on Enable NAT Traversal
- Turn on Clean up Active tunnels when Peer Gateway DNS name resolves to a different address
- Turn on Preserve IKE port for Pass Through Connections
Security Services>Gateway Anti-Virus
- If licensed, Enable Gateway Antivirus
- Configure Gateway AV Settings: Turn on Disable SMTP Responses
- Configure Gateway AV Settings: Turn off Disable detection of EICAR test virus
- Configure Gateway AV Settings: Turn on Enable HTTP Byte-Range requests with Gateway AV
- Configure Gateway AV Settings: Turn on Enable FTP REST request with Gateway AV
- Configure Gateway AV Settings: Turn off Enable HTTP Clientless Notification Alerts
Security Services>Intrusion Prevention
- If licensed, Enable IPS
- Turn on Prevent All and Detect All for High Priority Attacks
- Turn on Prevent All and Detect All for Medium Priority Attacks
- Turn on Prevent All and Detect All for Low Priority Attacks
Security Services>Anti-Spyware
- If licensed, Enable Anti-Spyware
- Turn on Prevent All and Detect All for High Priority Attacks
- Turn on Prevent All and Detect All for Medium Priority Attacks
- Turn on Prevent All and Detect All for Low Priority Attacks
- Configure Anti-Spyware Settings: Turn on Disable SMTP Responses
- Configure Anti-Spyware Settings: Turn off Enable HTTP Clientless Notification Alerts
AppFlow>Flow Reporting
- Turn on Send AppFlow To Local Collector
- Turn on Enable Real-Time Data Collection
Log>Log Monitor
- Set Logging Level: Debug
Log>Name Resolution
- Set Name Resolution Method to: DNS then NetBIOS
Internal Settings
- Turn on Protect against TCP State Manipulation DoS
- Turn on Apply IPS Signatures Bidirectionally
- Allow launching of AppFlow Monitor in a stand-alone browser frame
- Enable Visualization UI for Non-Admin/Config users
Source
http://www.sonicwall-sales.com/help-and-advice/sonicwall-one-touch-configuration.html
No comments:
Post a Comment