Firewall Planning
The planning phase for choosing and implementing a firewall can begin only after an organization has determined that a firewall is needed to enforce the organization’s security policy. This typically occurs following a risk assessment of the overall system.
A risk assessment includes :
- the identification of threats and vulnerabilities in the information system;
- the potential impact or magnitude of harm that a loss of confidentiality, integrity, or availability would have on the [..]
Network Layouts with Firewalls
The figure below shows a typical network layout with a hardware firewall device acting as a router. The unprotected side of the firewall connects to the single path labeled “WAN,” and the protected side connects to three paths labeled “LAN1,” “LAN2,” and “LAN3.” The firewall acts as a router for traffic between the Wide Area Network (WAN) path and [..]
Firewalls Testing
New firewalls should be tested and evaluated before deployment to ensure that they are working properly. Testing should be completed on a test network without connectivity to the production network. This test network should attempt to replicate the production network as faithfully as possible, including the network topology and network traffic that would travel through the firewall. Aspects of the solution to evaluate include the following:
- Connectivity. Users can establish and [..]