How Routers Enforce Perimeter Security Policy

Routers are used to secure the perimeter of networks. Three typical methods are as follows:

• In scenario 1, the router protects the LAN.

• In scenario 2, the router provides defense in depth by screening traffic before a firewall.

• In scenario 3, the zone between R1 and R2 is called a DMZ. Servers that must be accessible from the Internet can be put here.

Router 1 (R1)

Internet -

_h ^_

LAN 1

190.20.2.0

Scenario 1

R1 Firewall

Scenario 2

Scenario 2

DMZ Scenario 3

DMZ Scenario 3

A router provides a capability to help secure the perimeter of a protected network. It is a device where security action, based on the security policy of your organization, can be implemented.

To secure a network perimeter, a router can be deployed on its own. Scenario 1 in the figure shows a typical topology with the router being the component that connects the protected network, or internal LAN, to the Internet.

A router can also be used as part of a defense-in-depth approach as shown in scenario 2 in the figure. This approach is preferred to that of using only a router because it is more secure. The router acts as the first line of defense and, in such a deployment, is known as a screening router or perimeter router. It passes all connections intended for the internal LAN to the firewall. The firewall provides additional access control by tracking the state of the connections. The firewall denies the initiation of connections from the outside (untrusted) networks to the inside (trusted) network but allows the internal users to establish connections to the untrusted networks and permit the responses to come back through the firewall. It can also perform user authentication (authentication proxy) where users have to be authenticated before they can gain access to network resources.

Another approach, shown in scenario 3, is to offer an intermediate area, often called the demilitarized zone (DMZ). The DMZ can be used for servers that must be accessible from the Internet or some other external network. The firewall is set up to permit the required connections (for example, HTTP) from the outside (untrusted) networks to the public servers in the DMZ.

Securing Cisco Network Devices (SND) v2.0

© 2006 Cisco Systems, Inc.

Filtering with a Router

In all three scenarios in the last figure, the router is configured to apply traffic filters. A packet filter for IP services provides control of the data transfer between networks based on IP addresses, protocols, and ports. Some routers have packet filters that apply to network services in both inbound and outbound directions, while others have packet filters that apply only in one direction.

Continue reading here: The terminal can be a dumb terminal or a PC with terminal emulation software

Was this article helpful?

0 -1

Readers' Questions

  • luwam
    Is an intermediate area between a trusted network and an untrusted network?
    8 months ago
  • A demilitarized zone (DMZ) is the intermediate area between a trusted network and an untrusted network. It is a physical or logical sub-network that contains and exposes an organization's external-facing services to the DMZ while isolating the internal network. It allows access to the services while protecting the organization's internal network from attack by external users.
    • VIHTORI
      How would an edge router assist in securing perimeter of the organizational network?
      1 year ago
    • An edge router is a critical component of an organizational network and can be used to secure the perimeter of the network. It is responsible for implementing security policies, controlling the flow of traffic, and providing a secure gateway between the internal and external networks. The edge router can be used to filter and block traffic based on source or destination IP address or ports and can be used to control remote access to the network, such as using Virtual Private Networks (VPNs). It can also be used to encrypt data passing through the router, as well as to detect and block malicious traffic. By using an edge router, organizations can ensure that only authorized users and applications have access to their network.