
YuChakTinMichael‘sGIACGCFWProjectAssignment
Page 12
à InternalstaffsasVPNclientsaccessingexternalpartners’securesitesvia
PPTP
RAS:
Companystaffsareaccessingtheinhouseserverresourcesfromhomeorfrom
businesstripsviaRASdialin.RAStrafficdoesnotpassthroughtherouter.
ArchitectureOverview
A firewallisasystemdesignedtopreventunauthorizedaccesstoorfromaprivate
network. Itcanbeimplementedinbothhardwareandsoftware,oracombinationof
both.Sinceallmessagesenteringorleavingtheinternalnetworkmustpassthrough
thefirewallforsecurity examination,thefirewallitselfisapotentialbottleneck.Also,
regardlessofhowafirewallisimplemented,agoodfirewallproductcostsalargesum
ofmoney.
OurgoalforthesecurityarchitectureofGIACEnterpriseistosecureitsnetworkand
atthesametimeachieveabalancebetweensecurity,performanceandcost. To
achievesuchbalance,atthefrontlineweusehigherendsecurityproducts,whileat
thedepartmentallevelweusemoreeconomicalsolutions.
DesignPrincipleandTr adeoff
Theexhibitbelowshowsthatmultiplefirewallandroutingdevicesaredeployedin
thearchitecture.
Kommentare zu diesen Handbüchern