22.12.2012 Views

Front cover - IBM Redbooks

Front cover - IBM Redbooks

Front cover - IBM Redbooks

SHOW MORE
SHOW LESS

Create successful ePaper yourself

Turn your PDF publications into a flip-book with our unique Google optimized e-Paper software.

4.1 Infrastructure components<br />

116 Lotus Security Handbook<br />

Before we can describe policies and models for designing a secure network<br />

infrastructure, we must define and describe the typical components available.<br />

The high-level components we describe can be categorized as:<br />

► Firewalls<br />

► Routers, switches, and hubs<br />

► Proxies<br />

► Intrusion detection systems<br />

► Enterprise access management systems<br />

► Application servers<br />

Some components clearly perform network boundary functions, while others<br />

provide services within a network. Some components, such as application<br />

proxies, can perform both as boundary controls and network application servers.<br />

4.1.1 Firewall overview<br />

A definition from The American Heritage® Dictionary of the English Language,<br />

Fourth Edition:<br />

Firewall<br />

1. A fireproof wall used as a barrier to prevent the spread of fire.<br />

2. Computer Science. Any of a number of security schemes that prevent<br />

unauthorized users from gaining access to a computer network or that<br />

monitor transfers of information to and from the network.<br />

The term firewall is often misused or misunderstood because, in practice, a<br />

firewall is not necessarily one device, nor does it necessarily perform one<br />

function. Perhaps the confusion stems from the early use of the term firewall to<br />

describe single hardware devices that were essentially screening routers<br />

between two different IP networks. The term firewall has evolved to describe a<br />

variety of network defenses.<br />

For our purposes, a firewall is actually a system or a group of systems that<br />

provide some form of boundary, or more specifically, access control between two<br />

networks. A firewall provides two basic functions:<br />

– Permit traffic flow<br />

– Block traffic flow

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!