Home > Ask the Security Experts > Questions & Answers > The placement of security solutions on a network
Ask The Security Expert: Questions & Answers
EMAIL THIS

The placement of security solutions on a network

Stephen Mencik EXPERT RESPONSE FROM: Stephen Mencik

Pose a Question
Other Security Categories
Meet all Security Experts
Become an Expert for this site


Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us   


>
QUESTION POSED ON: 29 August 2001
I would like to know if you are aware of any diagram(s) which may show various types of security solutions (firewalls, VPNs, IDSs, etc.) and their place of deployment on a typical network. I would appreciate any help/leads that you could offer.


>

I'm sure there are such pictures somewhere on the Internet, but I could not find them quickly. So, below is a picture that I put together. I am not an artist, so please excuse the lack of fancy objects.

Diagram
Security solutions and their place of deployment on a typical network.

The most common place to insert a firewall or VPN device is right behind the gateway router that connects to the Internet. Typically, if both are used, they are used in parallel. I have also seen situations where a second firewall was added where the 'B' arrow is pointing. There are also devices which contain both a firewall and a VPN in the same box.

Intrusion-detection systems (IDSs) can actually be placed at many points. One of the most important spots is where the 'A' arrow is pointing. This can then detect intrusions that successfully get through either your VPN or firewall. Another location would be to place it between the gateway router and the Internet, to detect potential intrusions before they come into your network. If you place one there, do not neglect the inside IDS, as the outer one will not be able to detect any intrusions that may originate in other parts of your VPN, as that traffic will still be in the encrypted tunnel at that point. You can also have host-based IDS that, of course, will be installed on each of the hosts shown on the diagram.

It is also important to note that many modern routers have some firewall functionality, and some firewalls can also act as routers. In addition, both of those, plus VPN devices, provide logging that can be fed to an IDS. So, the picture presented is a very simplistic view of a network. However, it does provide a workable solution.

To determine what is best for your network, you should have a network security consultant work with your network engineer to come up with the best combination of products and services. You always need to balance security, throughput and cost in any risk management decision.


Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us   



RELATED RESOURCES
2020software.com, trial software downloads for accounting software, ERP software, CRM software and business software systems
Search Bitpipe.com for the latest white papers and business webcasts
Whatis.com, the online computer dictionary



Search and Browse the Expert Answer Center
Search and browse more than 25,000 question and answer pairs from more than 250 TechTarget industry experts.
Browse our Expert Advice



Find Security Solutions for Your Business
TechTarget Security Media
Information Security View this month\\'s issue and subscribe today.
Information Security Decisions Apply online for free conference admission.
SearchSecurity.com
HomeNewsMagazineMultimediaWhite PapersLearningAdviceTopicsEventsAbout Us

About Us  |  Contact Us  |  For Advertisers  |  For Business Partners  |  Site Index  |  RSS
TechTarget provides technology professionals with the information they need to perform their jobs - from developing strategy, to making cost-effective purchase decisions and managing their organizations' technology projects - with its network of technology-specific websites, events and online magazines.

TechTarget Corporate Web Site  |  Media Kits  |  Site Map




All Rights Reserved, Copyright 2003 - 2009, TechTarget | Read our Privacy Policy
  TechTarget - The IT Media ROI Experts