Network Segmentation Enforcement
Security Zone
Perimeter network Zone
Proxy server
Bastion Hosts
Screened Subnet
Firewall
- Blocks traffic that does not conform
Packet Filtering Firewal
Stateful Inspection Firewall
Appliance Firewall
Router Firewall
- Used by SOHO routers
Proxy Server
Forward Proxy
Transparent vs nontransparent proxy servers
Reverse proxy
NAT
Network Address Translation
PAT
Port Address Translation
Defense in Depth
- Examples are NAC, honeypots, separation of duties and intrusion detection
NAC
Honeypot
Separation of Duties
IDS
Intrusion Detection System
IPS
Intrusion Prevention System
Triple Homed Router