Building DMZs for Enterprise Networks

Part III :

Chapter List

Chapter 9: DMZ Router and Switch Security
Chapter 10: DMZ-Based VPN Services
Chapter 11: Implementing Wireless DMZs
Chapter 12: Sun Solaris Bastion Hosts

Introduction

When people think about securing their DMZs, they mostly think about firewalls, intrusion detection systems, VPNs, and hardening of servers within the DMZ. These are all parts of the process, but there is more to securing a DMZ than considering just these items. Some DMZ planners overlook hardening the routers or switches supporting the DMZ so that they cannot be exploited and used as tools to penetrate the network. Routers and switches connect all the devices on the DMZ to the enterprise network as well as the rest of the world; they are the devices that connect the bastion hosts, firewalls, VPNs, and intrusion detection systems to build the infrastructure. This makes routers and switches prime targets for hackers to exploit and glean information about the network they support or to use simply as springboards to other devices. Routers and switches on the DMZ, and anywhere else on the network, can also be used to protect resources that they connect via security features, including ACLs, VLANs, and private VLANs, to name a few. In this chapter, we present information on how to design and configure some important security features of routers and switches that enable them to run securely and protect the devices that they connect.

Securing the Router

In this section, we cover how routers are implemented within a DMZ environment. We discuss...

UNLIMITED FREE
ACCESS
TO THE WORLD'S BEST IDEAS

SUBMIT
Already a GlobalSpec user? Log in.

This is embarrasing...

An error occurred while processing the form. Please try again in a few minutes.

Customize Your GlobalSpec Experience

Category: Network Firewalls
Finish!
Privacy Policy

This is embarrasing...

An error occurred while processing the form. Please try again in a few minutes.