Security Rules

Given Guac sits in DMZ, with outbound internet access and internal network access, we need to be very careful around what we can allow the server access to. 
The server has restrictive access to the internal LAN, as well as external internet. 

Guac to Outbound

image.png

Internal LAN to Guac:

Only allows SSH and SSL access to the server, as well as ping sends and built-in Guac profile

image.png

Guac to Inbound:

Allows RDP SSH and VNC to specified servers

Also allows internal DNS access to DC's.

image.png


Revision #1
Created 31 July 2023 05:54:29 by Mitch Fraser
Updated 31 July 2023 06:06:38 by Mitch Fraser