12.07.2015 Views

31 Days Before Your CCNA Exam

31 Days Before Your CCNA Exam

31 Days Before Your CCNA Exam

SHOW MORE
SHOW LESS

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

274 <strong>31</strong> <strong>Days</strong> <strong>Before</strong> <strong>Your</strong> <strong>CCNA</strong> <strong>Exam</strong>Figure 8-2Typical Enterprise Internet Connection with a FirewallEnterprise IP NetworkC2www.example.comInternetC3FirewallAccessPointC1However, a firewall by itself is no longer adequate for securing a network. An integrated approachinvolving a firewall, intrusion prevention, and a virtual private network (VPN) might be necessary.An integrated approach to security and the devices necessary to make it happen follow these buildingblocks:■Threat control: Regulates network access, isolates infected systems, prevents intrusions, andprotects assets by counteracting malicious traffic. Cisco devices and applications that providethreat control solutions include the following:— Cisco ASA 5500 series Adaptive Security Appliances (ASA)— Integrated Services Routers (ISR)— Network admission control (NAC)— Cisco Security Agent for Desktops— Cisco intrusion prevention systems■■Secure communications: Secures network endpoints with a VPN. The devices that allow anorganization to deploy a VPN are Cisco ISR routers with a Cisco IOS VPN solution, and theCisco 5500 ASA and Cisco Catalyst 6500 switches.Network admission control: Provides a roles-based method of preventing unauthorizedaccess to a network. Cisco offers a NAC appliance.

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!