How Routers Enforce Perimeter Security Policy
Routers are used to secure the perimeter of networks. Three typical methods are as follows:
• In scenario 1, the router protects the LAN.
• In scenario 2, the router provides defense in depth by screening traffic before a firewall.
• In scenario 3, the zone between R1 and R2 is called a DMZ. Servers that must be accessible from the Internet can be put here.
|
Router 1 (R1) |
||
|
Internet - |
_h ^_ |
LAN 1 |
|
190.20.2.0 |
||
|
Scenario 1 |
R1 Firewall Scenario 2 Scenario 2 DMZ Scenario 3 DMZ Scenario 3A router provides a capability to help secure the perimeter of a protected network. It is a device where security action, based on the security policy of your organization, can be implemented. To secure a network perimeter, a router can be deployed on its own. Scenario 1 in the figure shows a typical topology with the router being the component that connects the protected network, or internal LAN, to the Internet. A router can also be used as part of a defense-in-depth approach as shown in scenario 2 in the figure. This approach is preferred to that of using only a router because it is more secure. The router acts as the first line of defense and, in such a deployment, is known as a screening router or perimeter router. It passes all connections intended for the internal LAN to the firewall. The firewall provides additional access control by tracking the state of the connections. The firewall denies the initiation of connections from the outside (untrusted) networks to the inside (trusted) network but allows the internal users to establish connections to the untrusted networks and permit the responses to come back through the firewall. It can also perform user authentication (authentication proxy) where users have to be authenticated before they can gain access to network resources. Another approach, shown in scenario 3, is to offer an intermediate area, often called the demilitarized zone (DMZ). The DMZ can be used for servers that must be accessible from the Internet or some other external network. The firewall is set up to permit the required connections (for example, HTTP) from the outside (untrusted) networks to the public servers in the DMZ. Securing Cisco Network Devices (SND) v2.0 © 2006 Cisco Systems, Inc. Filtering with a RouterIn all three scenarios in the last figure, the router is configured to apply traffic filters. A packet filter for IP services provides control of the data transfer between networks based on IP addresses, protocols, and ports. Some routers have packet filters that apply to network services in both inbound and outbound directions, while others have packet filters that apply only in one direction. |
Continue reading here: The terminal can be a dumb terminal or a PC with terminal emulation software
Was this article helpful?
Readers' Questions
-
luwam8 months ago
- Reply
-
VIHTORI1 year ago
- Reply