Figure 223 Security Level Example
[View full size imagel
In this example, a firewall is used to separate different areas of a network. The firewall has the following four interfaces:
• A connection to the Internet, assigned a low security level
® A connection to the DMZ, where public servers are located, assigned a medium security level
• A connection to a remote company that is working on a project for them, assigned a low security level ® A connection to the internal network, assigned a high security level
This company has assigned the following rules:
® High-to low-level access: permit
• Low- to high-level access: deny
• Same-level access: deny
Given these rules, the following traffic is allowed automatically to travel through the firewall:
• Internal devices to the DMZ, the remote company, and the Internet
• DMZ devices to the remote company and the Internet
Any other type of traffic flow is restricted. One advantage of this design is that, because the remote company and the Internet are assigned the same level, traffic from the Internet cannot reach the remote company (which provides protection), and the remote company cannot use your Internet access for free (which saves you money).
Another advantage of security levels is that they create a layered approach to security. For example, for either hackers on the Internet or the remote company to access internal resources in Figure 2-23, they probably first must hack into your DMZ and then use this as a stepping stone to hack into your internal network. Using this layered approach, you make the hacker's job much more difficult and your
This document was created by an unregistered ChmMagic, please go to http://www.bisenter.com to register it. Thanks network much more secure.
Continue reading here: Figure 228 Simple Firewall System Design
Was this article helpful?