Building DMZs for Enterprise Networks

In order to defend against attacks, we must first define just what the threats are. A threat is an intentional or unintentional act against something of value. Put simply, a threat is something bad that might happen to the item of value. The item of value could be a router, a firewall, or data itself. A vulnerability is a point of weakness in the defenses of the items of value. An attack (whether a passive or an active attack) is the act of finding or acting on the vulnerabilities of a system.
Today the firewall has become something of a commodity and is sold virtually everywhere. The marketing of the firewall has caused an indirect problem: Many people who purchase this commodity think that by using the firewall out of the box, the job of securing their network is completed. The reality is that their job has just begun, and if the task of securing the network is not finished, the entire network is still at risk of compromise. In today's world of threats from worms, viruses, intentional attacks, industrial espionage, and worse, a firewall is not enough.
Still, people think, "Yes, my network is protected I installed a firewall." The disturbing truth is that configuring the firewall is not very easy yet, even with the various Web and GUI front ends. You still have to have some knowledge of how packets travel across a network and what makes a good packet turn into a bad packet. In...