Create a customized Engine Template Policy

For a Common Criteria installation, add specific Access rules to a customized Engine Template Policy, then use that template to create security policies.

These steps are the high-level tasks. For more information, see the Creating and managing policy elements chapter in the Forcepoint Network Security Platform Product Guide.

Packet validity checks automatically drop invalid IP packets, packets with certain IP options, incomplete IP packets, and invalid IP fragments. These dropped packets are also logged when Packet Filter diagnostics have been enabled. The automatic anti-spoofing drops and logs spoofed packets where the source or the destination address is a loopback address, the source address is an IPv4 broadcast address or an IPv4 multicast address, or the source address does not belong to a connected network. The additional Access rules in the customized template discard IPv4 and IPv6 link local addresses, IPv6 reserved addresses, IPv4 and IPv6 addresses reserved for future use, and packets where the source address is an IPv6 multicast address.

For more details about the product and how to configure features, click Help or press F1.

Steps

  1. Open the Engine Template Policy for editing, then save it as Engine cPP Template.
  2. Create the following Network elements:
    • For IPv4, the "IPv4 Reserved for Future Use" network as 240.0.0.0/4.
    • For IPv6
      • The IPv6 networks 2d00:0000::/8, 2e00:0000::/7, and 3000:0000::/4 for RFC 3513 reserved addresses.
      • The Group element "RFC 3513 reserved addresses" that contains the networks above.
      • The IPv6 network "RFC 3513 Global Unicast Addresses" as 2000::/3.
      • The Expression element "IPv6 RFC 3513 reserved for future definition and use"

        (negation of a union):

        ~ ( "RFC 3513 Global Unicast Addresses"
        U "IPv6 Unspecified Address"
        U "Localhost"
        U "IPv6 Multicast Network"
        U "Link-Local IPv6 Unicast Addresses" )
  3. To add an Access rule, right-click the IPv4 Insert Point or IPv6 Insert Point, then select Add Rule.
    Tip: You can right-click the ID cell to add more Access rules and to move Access rules up and down in the Policy.
  4. To fill in the cell values for an Access rule, you can do the following:
    • Drag elements to the cell from the resource pane on the left.
    • Click the cell, then start typing to activate the look-ahead search.
    • Double-click the cell to open a dialog box where you can configure the settings.
  5. On the IPv4 Access tab, add the following rules to the beginning of the Access rules:
    Source Destination Service Action
    Link-Local IPv4 Unicast Addresses ANY ANY Discard
    ANY Link-Local IPv4 Unicast Addresses ANY Discard
    IPv4 Reserved for Future Use ANY ANY Discard
    ANY IPv4 Reserved for Future Use ANY Discard
  6. On the IPv4 Access tab, disable or delete the following rule:
    Source Destination Service Action
    ANY ANY Dest. Unreachable (Fragmentation Needed)

    Allow; Connection Tracking: Normal

  7. On the IPv6 Access tab, add the following rules to the beginning of the Access rules:
    Source Destination Service Action
    IPv6 RFC 3513 reserved addresses ANY ANY Discard
    ANY IPv6 RFC 3513 reserved addresses ANY Discard
    Link-Local IPv6 Unicast Addresses ANY ANY Discard
    ANY Link-Local IPv6 Unicast Addresses ANY Discard
    IPv6 Multicast Network ANY ANY Discard
    IPv6 RFC 3513 reserved for future definition and use ANY ANY Discard
    ANY IPv6 RFC 3513 reserved for future definition and use ANY Discard
  8. On the IPv6 Access tab, disable or delete the following rules:
    Source Destination Service Action
    ANY ANY IPv6 Neighbor Advertisement, IPv6 Neighbor Solicitation, IPv6 Redirect, IPv6 Router Advertisement, IPv6 Router Solicitation Allow; DoS Protection: off; Scan Detection: off
    ANY ANY IPv6 Packet Too Big Allow; Connection Tracking: Normal
  9. To allow IPv6 Neighbor Discovery, add the below rules before the IPv6 Insert Point. "IPv6 Solicited-Node Multicast" is defined as FF02::1:FF00:0/104.
    Note: You must define the IPv6 Solicited-Node Multicast network before you add the rules.
    Source Destination Service Action
    ANY IPv6 Solicited-Node Multicast IPv6 Neighbor Solicitation Allow
    $$ Local Cluster(NDI IPv6 addresses only) ANY IPv6 Neighbor Advertisement Allow
    ANY $$ Local Cluster(NDI IPv6 addresses only) IPv6 Neighbor Advertisement Allow
    Note:

    The IPv6 Neighbor Discovery Protocol can be adversely affected when link local IPv6 addresses are discarded as required in a Common Criteria configuration. To allow IPv6 Neighbor Solicitation and Neighbor Advertisement messages using IPv6 link local addresses, add the following rules before the IPv6 link local discard rules:

    Source Destination Service Action
    Link-Local IPv6 Unicast Addresses IPv6 Solicited-Node Multicast, Link-Local IPv6 Unicast Addresses IPv6 Neighbor Solicitation Allow
    RFC 3513 Global Unicast Addresses, Link-Local IPv6 Unicast Addresses Link-Local IPv6 Unicast Addresses IPv6 Neighbor Advertisement Allow