Network Security: A Practical Approach

The basic layout of a secure network
Firewalls
File and folder permissions
Network security presents a classic which came first problem: Where should we start discussing the details of risks and solutions? To understand vulnerabilities, you need to know some of the solutions; to understand the solutions, you need to understand vulnerabilities. (All together now: sigh.)
This chapter therefore provides you with introductory information about configuring a network so that it will support secure transmissions. We ll look at the layout of a secure network and at some very fundamental techniques for providing security, including firewalls (and DMZs), and setting file and folder permissions.
If you weren t concerned about network security, you could design a network topology primarily with performance in mind. Unfortunately, the world isn t that kind to us, and we therefore need to think about security not only in terms of software and human behavior, but also in terms of network design. The luckiest security professional in the universe is someone who has input to the design of the network before it is built. And if you come in after the network is up and running, you must be prepared to argue for necessary changes to the topology needed to support security measures.
It is very likely that a security professional will be called in years after a network has been in place. Someone has cracked the network and management doesn t want it to happen...