12. Choice of architecture: essential for effective protection
To build an effective, robust and flexible solution, a CISO needs to do more than simply configure a firewall and put it in front of the public network. He or she needs to think about how to combine the various components that make up the filtering policy, and the security policy in general. It's a question of defining a genuine firewall platform where firewall, DMZ, proxy and reverse-proxy coexist.
After introducing the concept of DMZ, and then the notion of VLAN, which is useful for setting up a more global security solution, this section discusses several firewall platform architectures, and, for each, presents the advantages and disadvantages. The aim is to enable CISOs to identify the key points to bear in mind when designing their own solution.
12.1 DMZ...
Exclusive to subscribers. 97% yet to be discovered!
Already subscribed? Log in!
Choice of architecture: essential for effective protection
Article included in this offer
"Security of information systems"
(
86 articles
)
Updated and enriched with articles validated by our scientific committees
A set of exclusive tools to complement the resources
Bibliography
Bibliography
- (1) - ANSSI - Recommandations pour la définition d'une politique de filtrage réseau d'un pare-feu. - mars 2013 https://www.ssi.gouv.fr/uploads/IMG/pdf/NP_Politique_pare_feu_NoteTech.pdf ...
Exclusive to subscribers. 97% yet to be discovered!
Already subscribed? Log in!