ZDNet UK


Skip to Main Content

ZDNet.co.uk - Winner of Best Business Website 2007
  1. Home
  2. News
  3. Blogs
  4. Reviews
  5. Prices
  6. Resources
  7. Community
  8. My ZDNet

 

ZDNet UK RSS Feeds


IT Jobs

Network management Toolkit

Multilayer firewall strategy

Mitch Bryant

Published: 14 Feb 2003 21:07 GMT

  • Email
  • Trackback
  • Clip Link
  • Print friendly
  • Post Comment

While firewalls can secure Internet access, protect mission-critical information, and leverage the Internet to connect a global enterprise, they're just the starting point for building a security fortress. Some organisations may believe they're secure with current firewalls in place, but it won't be long before they realise they need more tools for securing their next connectivity initiative, such as a VPN.

Whether you want to improve, replace, or initially install a firewall, it's a good time to refresh your knowledge of firewalls and understand the vital steps, such as developing a security policy, that you must take before making any more security moves.

False firewall beliefs
A common misconception is that one firewall can protect every asset. While that might have been true a few years ago, it's not enough protection, given the advancements in hacking and increasing external threats.

According to the CERT Coordination Center at the Software Engineering Institute (CERT/CC), the number of reported network security incidents has almost tripled in the past two years -- from 21,756 in 2000 to 73,359 at the end of Q3 2002.

A second misconception is that a firewall device is a "connect, turn on, and forget about it" device. It's actually a technology that requires constant review, fine-tuning, and evaluation.

In addition, many organisations plug firewalls into place without a security policy. Firewall deployment should be tied directly to security policies that address and support your company's objectives. Enterprises must consider a multilayered security approach, with a security policy, firewalls, and additional security tools (such as virus software).

What a firewall can and can't do
A firewall can be hardware- or software-based. The tightest security is obtained when the two options are used in combination. Yet, even in this approach, a firewall system has its limits:

  • It can't protect the enterprise from attacks and threats from within your network.
  • Virus protection is limited without additional software and specialised technologies.
  • A firewall can't protect an organisation from attacks that avoid a firewall -- an external hack via a dial-up account can fully compromise the entire security plan.

Firewall technology, obviously, also can't protect organisations from employee carelessness or mistakes with passwords and unauthorised access. Only specific tools and policy guidelines on expected computer use and access can thwart those issues.

Next

Previous

1 2


  • Email
  • Trackback
  • Clip Link
  • Print friendly Print with Kyocera

Did you find this article useful?
98 out of 220 people found this useful


Full Talkback thread

0 comments


Company/Topic Alerts

Create a new alert from the list below:














Related Jobs

Oracle DBA - Database Management Non-Live

Essential Skills and experience Required: - Oracle administration.i, 9i, 10G) - Database tuning and capacity management skills - Standby databases - ...

Network Security Administrator Level 2 (CCNA, CCNP)

Your role will comprise of; - Performing required maintenance for installation, configuration, and updates to firewalls, and VPN connections - ...

Windows 2003 Network support - Devon

Exchange Server and Firewall technology then you have a great prospect of being short-listed for interview. DHCP, WINS & Group Policy. I have an ...

Featured Talkback

Could it be that ISP’s are making this out to be a bigger problem than it actually is? We’re a small country with an internet penetration of less than 60%, for every Youtuber there’s someone who only uses the internet to check their emails, more people surf on their mobile handsets than a few years ago. Surely things should even themselves up.

By: harpless

Read full story:
Unlimited-broadband offers to go 'within a year'

On The Road Blog

Mobile Open Source: A Torrent of Impli...

Mobile Open Source: A Torrent of Implication Author: Eric Everson, Founder MyMobiSafe.com There is a change working its way through the wireless industry that is fraught with the... More

Post a comment

TokBox - A Nice, Simple VideoChat Alte...

I have FINALLY had the time to take at least a quick look at TokBox, which was recommended to me in a comment on a previous blog post. First, I'm sorry that it has taken this long.... More

1 comment

Skype's Abysmal Service - An Independe...

Here is an excellent review and tests of Skype service in the U.K. In a nutshell, dropped calls, poor quality, no response from Skype. Skype Drops the Ball on Free Calls I would... More

Post a comment