Firewalls: Jumpstart for Network and Systems Administrators

Vacca, John R.; Ellis, Scott

In stock
Regular price 13.750 KD inc. VAT
License
Table of contents
  • Cover
  • Copyright Pageiv
  • Contentsvii
  • Forewordxvii
  • Introductionxix
  • Acknowledgmentsxxix
  • Section I: Overview of Firewall Technology1
  • Chapter 1. Firewalls: What Are They?3
  • 1.1 Chapter objectives3
  • 1.2 Firewall defined7
  • 1.3 Why firewalls?8
  • 1.4 Benefits of firewalls12
  • 1.5 Enhanced privacy15
  • 1.6 Limitations of firewalls16
  • 1.7 Summary19
  • 1.8 References21
  • Chapter 2. Type of Firewall Security Policy23
  • 2.1 Chapter objectives23
  • 2.2 Firewall protection24
  • 2.3 Firewall architectures25
  • 2.4 Types of firewalls26
  • 2.5 Issues29
  • 2.6 Intranet32
  • 2.7 Network trust relationships33
  • 2.8 Virtual private networks34
  • 2.9 Firewall administration34
  • 2.10 Revision/update of firewall policy41
  • 2.11 Examples of service-specific policies43
  • 2.12 Summary48
  • 2.13 References48
  • Chapter 3. Firewall Types49
  • 3.1 Chapter objectives49
  • 3.2 Types of firewalls50
  • 3.3 Understanding firewall types55
  • 3.4 Firewall types drawbacks55
  • 3.5 Summary56
  • 3.6 References57
  • Section II: Firewall Topologies59
  • Chapter 4. Choosing the Right Firewall61
  • 4.1 Chapter objectives61
  • 4.2 Convergence63
  • 4.3 About packet inspection72
  • 4.4 Summary90
  • Chapter 5. Defense in Depth: Firewall Topologies93
  • 5.1 Chapter objectives93
  • 5.2 Virtual private network94
  • 5.3 Firewall policies97
  • 5.4 Setting up a demilitarized zone:A VPN alternative?100
  • 5.5 Summary110
  • Section III: Firewall Installation and Configuration111
  • Chapter 6. Installation Preparation113
  • 6.1 Chapter objectives113
  • 6.2 Unbreakable walls114
  • 6.3 Selecting an operating system115
  • 6.4 Scanning for vulnerabilities124
  • 6.5 Summary129
  • Chapter 7. Firewall Configuration131
  • 7.1 Chapter objectives131
  • 7.2 Defining firewall security objects131
  • 7.3 Scanning the firewall and fixing vulnerabilities135
  • 7.4 Identifying trusted and untrusted networks142
  • 7.5 Summary145
  • Section IV: Supporting Outgoing Services Through Firewall Configuration147
  • Chapter 8. Simple Policy Implementation149
  • 8.1 Chapter objectives149
  • 8.2 Policy configuration150
  • 8.3 Supporting HTTP153
  • 8.4 Dynamic content156
  • 8.5 Summary157
  • Chapter 9. Complex Web Services Management159
  • 9.1 Chapter objectives159
  • 9.2 Telnet161
  • 9.3 FTP161
  • 9.4 Handling port numbers165
  • 9.5 Deploying Real Audio170
  • 9.6 Summary172
  • Chapter 10. Content Filtering175
  • 10.1 Chapter objectives175
  • 10.2 Filtering out dangerous content175
  • 10.3 Summary184
  • Section V: Secure External Services Provision185
  • Chapter 11. Publicly Accessible Servers Implementation187
  • 11.1 Chapter objectives187
  • 11.2 Securing your organization’s Internet site187
  • 11.3 Separating your Internet site from your intranet197
  • 11.4 Supporting SMTP mail architectures199
  • 11.5 Summary201
  • Chapter 12. Architecture Selection203
  • 12.1 Chapter objectives203
  • 12.2 Types of screened subnet architectures203
  • 12.3 Single-box architecture213
  • 12.4 Summary215
  • Chapter 13. External Servers Protection217
  • 13.1 Chapter objectives217
  • 13.2 Siting external servers on a perimeter net217
  • 13.3 Deploying packet filtering to control access to your servers225
  • 13.4 Router packet filtering226
  • 13.5 Using router access control lists227
  • 13.6 Summary227
  • Section VI: Internal IP Services Protection229
  • Chapter 14. Internal IP Security Threats: Beyond the Firewall231
  • 14.1 Chapter objectives231
  • 14.2 Network threats232
  • 14.3 Organization risk assessment236
  • 14.4 Examining inside attacks238
  • 14.5 Handling new threats239
  • 14.6 Antivirus software technology: Beyond the firewall240
  • 14.7 Summary247
  • 14.8 References247
  • Chapter 15. Network Address Translation Deployment249
  • 15.1 Chapter objectives249
  • 15.2 Person-to-person communication249
  • 15.3 Internet protocol telephony250
  • 15.4 Routers, firewalls, and NATs251
  • 15.5 Handling SIP251
  • 15.6 Firewall traversal/SIP NAT252
  • 15.7 Employing a Linux-based SOHO firewall solution with NAT technology253
  • 15.8 Summary267
  • 15.9 References268
  • Section VII: Firewall Remote Access Configuration269
  • Chapter 16. Privacy and Authentication Technology271
  • 16.1 Chapter objectives271
  • 16.2 Selecting cryptographic algorithms through encryption273
  • 16.3 Key management275
  • 16.4 Auditing, authentication, and authorization276
  • 16.5 High availability and load balancing278
  • 16.6 Transport and network278
  • 16.7 Encryption of multiple columns: database considerations279
  • 16.8 Summary282
  • 16.9 References283
  • Chapter 17. Tunneling: Firewall-to-Firewall285
  • 17.1 Chapter objectives285
  • 17.2 Increasing risk on extranets and intranets286
  • 17.3 Openness with protection of firewall tunneling and Internet security solutions286
  • 17.4 Firewall tunneling and Internet security architecture technologies287
  • 17.5 Firewall tunneling technologies289
  • 17.6 Demilitarized zone focus291
  • 17.7 Keeping the firewall tunneling security rules up-to-date through enterprise intranets292
  • 17.8 Summary293
  • 17.9 References295
  • Section VIII: Firewall Management297
  • Chapter 18. Auditing and Logging299
  • 18.1 Chapter objectives299
  • 18.2 Auditing your firewall299
  • 18.3 Logging302
  • 18.4 Summary308
  • 18.5 References309
  • Chapter 19. Firewall Administration311
  • 19.1 Chapter objectives311
  • 19.2 System administration312
  • 19.3 Managing your firewall remotely312
  • 19.4 Maintenance of a firewall317
  • 19.5 Managing firewall security321
  • 19.6 Summary326
  • 19.7 References327
  • Chapter 20. Summary, Conclusions, and Recommendations329
  • 20.1 Chapter objectives329
  • 20.2 Summary330
  • 20.3 Conclusions331
  • 20.4 Recommendations332
  • 20.5 References339
  • Section IX: Appendixes341
  • A. Contributors of Firewall Software343
  • B. Worldwide Survey of Firewall Products349
  • C. Firewall Companies353
  • D. Commercial Products or Consultants Who Sell or Service Firewalls357
  • E. Establishing Your Organization’s Security363
  • F. Network Interconnections: A Major Point of Vulnerability367
  • G. Deterring Masqueraders and Ensuring Authenticity371
  • H. Preventing Eavesdropping to Protect Your Privacy381
  • I. Thwarting Counterfeiters and Forgery to Retain Integrity Through a Reverse Firewall385
  • J. Avoiding Disruption of Service to Maintain Availability391
  • K. Developing Your Firewall Security Policy393
  • Glossary397
  • Index407
Book details
  • Vendor Elsevier S & T
  • SKU 9781555582975R180
  • ISBN-13 9780080491325
  • Author Vacca, John R.; Ellis, Scott
  • Category Computers
  • Subject General

Do you have questions about this book?

Ask an expert!

In this book, you will gain extensive hands-on experience installing and configuring a firewall. You will also learn how to allow access to key Web services while maintaining your organization's security, as well as how to implement firewall-to-firewall virtual private networks (VPNs). You will learn how to build a firewall to protect your network; provide access to HTTP and FTP services on the Internet, and implement publicly accessible servers without compromising security. Furthermore, throughout the book, extensive hands-on examples provide you with practical experience in establishing security with firewalls. Examples include, but are not limited to: Installing and configuring Check Point FireWall-1; scanning to validate configuration using ISS Internet Scanner; configuring the firewall to support simple and complex Web services; setting up a packet filtering router; enhancing firewall configurations to support split-DNS; authenticating remote users; and protecting browsers and servers with a proxy-based firewall.

· Install and configure proxy-based and stateful-filtering firewalls
· Protect internal IP addresses with NAT and deploy a secure DNS architecture
· Develop an Internet/intranet security policy to protect your organization's systems and data
· Reduce your susceptibility to an attack by deploying firewalls, data encryption and decryption and other countermeasures