How to Make a Firewall Sandwich
- 05 February, 2002 13:14
- Comments
Here's a nice recipe for making a tasty, high-performance security checkpoint to replace a bland, low-performing single point of failure at the border between your network and the Internet.
FIREWALL SANDWICH - Serves one (1) enterprise gatewayINGREDIENTS2 load-balancing switches, fresh 1GB type is best 2 to 60 firewalls, to taste (see number four below) 1 bushel of Cat 5 Ethernet wiring, separated 1 PC with firewall management software 1 Internet connection 1 ounce of freshly prepared security policy Parsley sprigs.
DIRECTIONS
1. Sprinkle security policy until it coats the entire enterprise.
2. Install management software on a PC. Use it to create the rules the firewalls will use to filter traffic coming in and going out of the network. Set aside with Internet connection.
3. At edge of the network, put in 1 load-balancing switch so that the end connecting to the Internet faces out. (The load balancers will make sure no single firewall is overloaded with traffic. They will also move traffic to a working firewall if another firewall breaks down.) Let sit.
4. Place firewalls behind switch. Depending on taste, place as few as 2 or as many as 60 or more firewalls in the sandwich. More firewalls will yield higher performance and less chance of failure.
5. Interconnect firewalls using Cat 5 Ethernet wiring (see picture). Also, connect firewalls to management PC for configuration.
6. Put second load-balancing switch behind firewalls.
7. Connect the switches to the firewalls with remaining Cat 5 wiring.
8. Plug Internet connection into the front switch and enterprise connection into the back switch.
9. Plug in power supplies. Turn all boxes on.
10 Decorate with parsley sprigs.
11. Serve in a cool room, 24/7.
Bon appA©tit!
Join the CIO Australia group on LinkedIn. The group is open to CIOs, IT Directors, COOs, CTOs and senior IT managers.
- Bookmark this page
- Share this article
- Got more on this story? Email CIO
- Follow CIO on twitter
- The Big Six: The CIO Executive Council’s Frameworks for IT Value and Leadership
- The Pathways ICT Leadership Development Program Brochure and Curriculum 2012
- Pathways Advanced ICT Leadership Development Program Brochure and Course Outline 2012
- Detailed Explanation of the Core Competencies
- Sample: Individual Stand Alone Core Competency Report
-
Australia's first 4G smartphone is the HTC Velocity 4G
-
Swedish e-commerce startup's execs linked to NYC sex crime
-
Face Time - Interview with John Brennan and Robert DiStefano
-
How to implement next-generation storage infrastructure for Big Data
-
Pfizer's Future Depends on IT Transformation
-
Key Considerations in Modernising Your Backup and Deduplication Solutions
There is a definite need for better data backup solutions in today’s enterprise data centers. The question is whether to continue with software-only backup and deduplication solutions, or to make the move to a purpose-built backup appliance with deduplication capabilities. This paper provides a structured approach to assessing the advantages of the appliance model. Read this whitepaper. -
Traditional Backup is Dead - Are you prepared?
Conventional backup and recovery approaches clearly can't keep up with ever-growing storage rates. It's time to take on a new strategy. -
Shedding Light on Backup and Availability Challenges in Virtual Environments
This IDG white paper explores specific backup and availability challenges organisations must surmount as they move to virtualise their business-critical applications. It then shows how attaining proper service levels for these applications requires a high degree of visibility into the VMware virtual environment.
-
Wrox's Visual C# 2005 Express Edition Starter Kit
-
Mastering Visual C# .Net
-
C++ Courseware Student Version Adapted From Horstmann C++ Essentials
-
The Art of Indexing
-
Mastering Data Mining
-
Professional Alfresco
-
Zbrush Character Creation, 2nd Edition
-
Master Visually Microsoft Office 2007
-
Outlook 2003 Bible








Comments
Post new comment