Image
 
linkedin_logo.png rss_logo.jpg
twitter_logo.png youtube_logo.jpg
Latest Additions
 
EH-Net Login
Welcome Guest.






Lost Password?
No account yet? Register
Who's Online
We have 78 guests online
EH-Net News Feeds
Latest Additions
 
Advertisement

You are here: Home arrow Forum arrow Ethical Hacking Discussions and Related Certificationsarrow General Certificationarrow Networkingarrow Secure Network Design
EH-Net
May 26, 2012, 02:19:35 AM *
Welcome, Guest. Please login or register.
Did you miss your activation email?

Login with username, password and session length
News: Advertise on EH-Net!! - Reasonable Rates, Highly Targeted Audience.
 
   Home   Help Calendar Login Register  
Pages: [1]   Go Down
  Print  
Author Topic: Secure Network Design  (Read 5122 times)
0 Members and 1 Guest are viewing this topic.
knwminus
Jr. Member
**
Offline Offline

Posts: 99



View Profile WWW
« on: December 20, 2010, 05:48:53 PM »

Greetings,

For those of you that design networks or suggest designs do you still feel that layer firewalls (from different vendors) is still a valuable part of defensive in depth? From your experience, do companies tend to use this in the SMB enterprises?

Just want to get someone else's perspective. I am submitting a proposal for our new network design on Wednesday and the other guy and I have some very, very different opinions.

Thanks,

Logged

A+ N+ CCNA CCNA:S CNSS 4011 Security+

Next Up: CCNP CCNP:S
rdm
Newbie
*
Offline Offline

Posts: 9


View Profile
« Reply #1 on: December 20, 2010, 07:22:52 PM »

I work for a medium sized business and we use several firewalls both on the edge and to segment internal networks.
Logged

GCIA, CEH, Security+
hell_razor
Jr. Member
**
Offline Offline

Posts: 83


View Profile
« Reply #2 on: December 21, 2010, 08:49:16 AM »

Personally, as long as you are using a "good" firewall (easy to administer, secure, works for you), then I would not go with a different vendor if the same group will be administering a lot of other equipment as well.  I do not think the overhead is worthwhile, and particularly not so if you use firewall management software from the same vendors (logging, configuration management, etc.).
Logged

A+, Network+, Server+, CISSP, GSEC, GCIH, GPEN, GCIA, GISP, GCFW
chrisj
Hero Member
*****
Offline Offline

Posts: 997


View Profile
« Reply #3 on: December 21, 2010, 10:26:08 AM »

It's not just the firewall that you would use to segment things.

Personally, I'd firewall the network connection to the internet and DMZ. Internally, I'd use vlans and access lists to limit exposure.
Logged

OSWP, Sec+
knwminus
Jr. Member
**
Offline Offline

Posts: 99



View Profile WWW
« Reply #4 on: December 21, 2010, 12:33:20 PM »

Oh we will be using vlans in our new design. I personally feel like since I am the one who will be handling the firewall admin work, I should stick with one vendor and expertly configure it and use a solid IDS implementation to pick up the slack.


I think I might post my idea for the new network design later.
Logged

A+ N+ CCNA CCNA:S CNSS 4011 Security+

Next Up: CCNP CCNP:S
rabray
Newbie
*
Offline Offline

Posts: 38


View Profile
« Reply #5 on: January 14, 2011, 07:13:38 PM »

Rather than an IDS, would you not perhaps consider a IPS or IDPS?

You may already have that in mind, but you know those acroynms, often confusion can creep in.

Sometimes the kind of thing that can cause a configuration issue by misunderstanding or lack of procedures (or lack of following of procedure)

Logged

---------------------------------------
CEH, eCPPT, MCT, MCSA, MCDST, A+, Net+

Never been the flamin type.
Pages: [1]   Go Up
  Print  
 
Jump to:  

Powered by MySQL Powered by PHP Powered by SMF 1.1.16 | SMF © 2011, Simple Machines
Joomla Bridge by JoomlaHacks.com
Valid XHTML 1.0! Valid CSS!
Page created in 0.084 seconds with 23 queries.
 

gk_static-ad_feb2012.jpg
Global Knowledge: Build Security Skills to Protect & Defend

els_130x200fixed2.gif
eLearnSecurity Student Course Now Live!
5% Off with Code
ELS-EH-5

SANS Deals 4 EH-Netters
$150 OFF Any SANS Course in Any Format!
Coupon Code: EHN_Connect Including SANS Security West 2012 & SANSFIRE 2012
Recent Forum Topics

cbtnuggets_logo_125.jpg
Try CBT Nuggets Free!

Vote For EH-Net

Add to Technorati Favorites
technorati fave

 
         
Advertisement

© 2012 The Ethical Hacker Network
Joomla! is Free Software released under the GNU/GPL License.