Characterizations of What's Allowed and What's Not
Initiates Flow
Receives Flow
Protocol(s)
Allowed?
Internal client (such a C2)
Any internal server
POP3, SMTP, HTTP, FTP, and so on
Yes
Internal client (such as C2)
www.fredsco.com web server
HTTP
Yes
Internal client (such as C2)
Internet-based servers
HTTP and FTP
Yes
Internal mail server
External mail server
SMTP
Yes
External mail server
Internal mail server
SMTP
Yes
Any internal host
Any Internet host
Any protocols that are not otherwise specified
No
Internet clients
www.fredsco.com web server
HTTP
Yes
Internet clients
Any host inside Fredsco
Any protocols that are not otherwise specified
No
If you don't remember the protocols mentioned in the table, the
details are covered in Chapter 8,
"Shipping Goods over a (Network) Roadway." For the purposes of this chapter,
just remember that e-mail clients use POP3 to retrieve mail, that e-mail servers
use SMTP to transfer mail to other servers, that HTTP is used for web traffic,
and that FTP is used to transfer files.