19.12.2012 Views

IT Baseline Protection Manual - The Information Warfare Site

IT Baseline Protection Manual - The Information Warfare Site

IT Baseline Protection Manual - The Information Warfare Site

SHOW MORE
SHOW LESS

Create successful ePaper yourself

Turn your PDF publications into a flip-book with our unique Google optimized e-Paper software.

Safeguard Catalogue - Communications Remarks<br />

____________________________________________________________________ .........................................<br />

LAN 1<br />

____________________________________________________________________ .........................................<br />

<strong>IT</strong>-<strong>Baseline</strong> <strong>Protection</strong> <strong>Manual</strong>: Oktober 2000<br />

LAN 2<br />

LAN 3<br />

Figure 2:<br />

Physical segmentation in compliance with Figure 1<br />

On the basis of VLAN-compatible network components, virtual LANs can be<br />

formed without any physical restructuring. In accordance with the<br />

technologies used, these VLANs are created through segmentation on layers 2<br />

and 3. Like LAN segmentation, this allows a network to be separated into<br />

areas where high demands are placed on the confidentiality of data, for<br />

example (refer to S 5.61 Suitable physical segmentation). Depending on the<br />

product in use, different functions are available for the formation of VLANs.<br />

Some products allow the formation of VLANs on layers 2 and 3, which can<br />

only be coupled by means of routers (and are thus termed secure VLANs). In<br />

this case, filter rules need to be defined for the router in order to ensure<br />

controlled transmissions between the individual VLANs. Other manufacturers<br />

even implement a routing function in layer-3 switches, which allows VLANS<br />

to be linked without the need for additional routers. In particular, the intended<br />

technologies and products must be checked to determine whether they fulfill<br />

requirements concerning the confidentiality and integrity of data.

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!