Figure 223 Security Level Example

[View full size imagel

Firewall Security Level

In this example, a firewall is used to separate different areas of a network. The firewall has the following four interfaces:

• A connection to the Internet, assigned a low security level

® A connection to the DMZ, where public servers are located, assigned a medium security level

• A connection to a remote company that is working on a project for them, assigned a low security level ® A connection to the internal network, assigned a high security level

This company has assigned the following rules:

® High-to low-level access: permit

• Low- to high-level access: deny

• Same-level access: deny

Given these rules, the following traffic is allowed automatically to travel through the firewall:

• Internal devices to the DMZ, the remote company, and the Internet

• DMZ devices to the remote company and the Internet

Any other type of traffic flow is restricted. One advantage of this design is that, because the remote company and the Internet are assigned the same level, traffic from the Internet cannot reach the remote company (which provides protection), and the remote company cannot use your Internet access for free (which saves you money).

Another advantage of security levels is that they create a layered approach to security. For example, for either hackers on the Internet or the remote company to access internal resources in Figure 2-23, they probably first must hack into your DMZ and then use this as a stepping stone to hack into your internal network. Using this layered approach, you make the hacker's job much more difficult and your

This document was created by an unregistered ChmMagic, please go to http://www.bisenter.com to register it. Thanks network much more secure.

Continue reading here: Figure 228 Simple Firewall System Design

Was this article helpful?

0 0