Firewalls: Jumpstart for Network and Systems Administrators
Vacca, John R.; Ellis, Scott
In stock
Regular price
13.750 KD
inc. VAT
Couldn't load pickup availability
Table of contents
- Cover
- Copyright Pageiv
- Contentsvii
- Forewordxvii
- Introductionxix
- Acknowledgmentsxxix
- Section I: Overview of Firewall Technology1
- Chapter 1. Firewalls: What Are They?3
- 1.1 Chapter objectives3
- 1.2 Firewall defined7
- 1.3 Why firewalls?8
- 1.4 Benefits of firewalls12
- 1.5 Enhanced privacy15
- 1.6 Limitations of firewalls16
- 1.7 Summary19
- 1.8 References21
- Chapter 2. Type of Firewall Security Policy23
- 2.1 Chapter objectives23
- 2.2 Firewall protection24
- 2.3 Firewall architectures25
- 2.4 Types of firewalls26
- 2.5 Issues29
- 2.6 Intranet32
- 2.7 Network trust relationships33
- 2.8 Virtual private networks34
- 2.9 Firewall administration34
- 2.10 Revision/update of firewall policy41
- 2.11 Examples of service-specific policies43
- 2.12 Summary48
- 2.13 References48
- Chapter 3. Firewall Types49
- 3.1 Chapter objectives49
- 3.2 Types of firewalls50
- 3.3 Understanding firewall types55
- 3.4 Firewall types drawbacks55
- 3.5 Summary56
- 3.6 References57
- Section II: Firewall Topologies59
- Chapter 4. Choosing the Right Firewall61
- 4.1 Chapter objectives61
- 4.2 Convergence63
- 4.3 About packet inspection72
- 4.4 Summary90
- Chapter 5. Defense in Depth: Firewall Topologies93
- 5.1 Chapter objectives93
- 5.2 Virtual private network94
- 5.3 Firewall policies97
- 5.4 Setting up a demilitarized zone:A VPN alternative?100
- 5.5 Summary110
- Section III: Firewall Installation and Configuration111
- Chapter 6. Installation Preparation113
- 6.1 Chapter objectives113
- 6.2 Unbreakable walls114
- 6.3 Selecting an operating system115
- 6.4 Scanning for vulnerabilities124
- 6.5 Summary129
- Chapter 7. Firewall Configuration131
- 7.1 Chapter objectives131
- 7.2 Defining firewall security objects131
- 7.3 Scanning the firewall and fixing vulnerabilities135
- 7.4 Identifying trusted and untrusted networks142
- 7.5 Summary145
- Section IV: Supporting Outgoing Services Through Firewall Configuration147
- Chapter 8. Simple Policy Implementation149
- 8.1 Chapter objectives149
- 8.2 Policy configuration150
- 8.3 Supporting HTTP153
- 8.4 Dynamic content156
- 8.5 Summary157
- Chapter 9. Complex Web Services Management159
- 9.1 Chapter objectives159
- 9.2 Telnet161
- 9.3 FTP161
- 9.4 Handling port numbers165
- 9.5 Deploying Real Audio170
- 9.6 Summary172
- Chapter 10. Content Filtering175
- 10.1 Chapter objectives175
- 10.2 Filtering out dangerous content175
- 10.3 Summary184
- Section V: Secure External Services Provision185
- Chapter 11. Publicly Accessible Servers Implementation187
- 11.1 Chapter objectives187
- 11.2 Securing your organization’s Internet site187
- 11.3 Separating your Internet site from your intranet197
- 11.4 Supporting SMTP mail architectures199
- 11.5 Summary201
- Chapter 12. Architecture Selection203
- 12.1 Chapter objectives203
- 12.2 Types of screened subnet architectures203
- 12.3 Single-box architecture213
- 12.4 Summary215
- Chapter 13. External Servers Protection217
- 13.1 Chapter objectives217
- 13.2 Siting external servers on a perimeter net217
- 13.3 Deploying packet filtering to control access to your servers225
- 13.4 Router packet filtering226
- 13.5 Using router access control lists227
- 13.6 Summary227
- Section VI: Internal IP Services Protection229
- Chapter 14. Internal IP Security Threats: Beyond the Firewall231
- 14.1 Chapter objectives231
- 14.2 Network threats232
- 14.3 Organization risk assessment236
- 14.4 Examining inside attacks238
- 14.5 Handling new threats239
- 14.6 Antivirus software technology: Beyond the firewall240
- 14.7 Summary247
- 14.8 References247
- Chapter 15. Network Address Translation Deployment249
- 15.1 Chapter objectives249
- 15.2 Person-to-person communication249
- 15.3 Internet protocol telephony250
- 15.4 Routers, firewalls, and NATs251
- 15.5 Handling SIP251
- 15.6 Firewall traversal/SIP NAT252
- 15.7 Employing a Linux-based SOHO firewall solution with NAT technology253
- 15.8 Summary267
- 15.9 References268
- Section VII: Firewall Remote Access Configuration269
- Chapter 16. Privacy and Authentication Technology271
- 16.1 Chapter objectives271
- 16.2 Selecting cryptographic algorithms through encryption273
- 16.3 Key management275
- 16.4 Auditing, authentication, and authorization276
- 16.5 High availability and load balancing278
- 16.6 Transport and network278
- 16.7 Encryption of multiple columns: database considerations279
- 16.8 Summary282
- 16.9 References283
- Chapter 17. Tunneling: Firewall-to-Firewall285
- 17.1 Chapter objectives285
- 17.2 Increasing risk on extranets and intranets286
- 17.3 Openness with protection of firewall tunneling and Internet security solutions286
- 17.4 Firewall tunneling and Internet security architecture technologies287
- 17.5 Firewall tunneling technologies289
- 17.6 Demilitarized zone focus291
- 17.7 Keeping the firewall tunneling security rules up-to-date through enterprise intranets292
- 17.8 Summary293
- 17.9 References295
- Section VIII: Firewall Management297
- Chapter 18. Auditing and Logging299
- 18.1 Chapter objectives299
- 18.2 Auditing your firewall299
- 18.3 Logging302
- 18.4 Summary308
- 18.5 References309
- Chapter 19. Firewall Administration311
- 19.1 Chapter objectives311
- 19.2 System administration312
- 19.3 Managing your firewall remotely312
- 19.4 Maintenance of a firewall317
- 19.5 Managing firewall security321
- 19.6 Summary326
- 19.7 References327
- Chapter 20. Summary, Conclusions, and Recommendations329
- 20.1 Chapter objectives329
- 20.2 Summary330
- 20.3 Conclusions331
- 20.4 Recommendations332
- 20.5 References339
- Section IX: Appendixes341
- A. Contributors of Firewall Software343
- B. Worldwide Survey of Firewall Products349
- C. Firewall Companies353
- D. Commercial Products or Consultants Who Sell or Service Firewalls357
- E. Establishing Your Organization’s Security363
- F. Network Interconnections: A Major Point of Vulnerability367
- G. Deterring Masqueraders and Ensuring Authenticity371
- H. Preventing Eavesdropping to Protect Your Privacy381
- I. Thwarting Counterfeiters and Forgery to Retain Integrity Through a Reverse Firewall385
- J. Avoiding Disruption of Service to Maintain Availability391
- K. Developing Your Firewall Security Policy393
- Glossary397
- Index407
Book details
- Vendor Elsevier S & T
- SKU 9781555582975R180
- ISBN-13 9780080491325
- Author Vacca, John R.; Ellis, Scott
- Category Computers
- Subject General
Do you have questions about this book?
In this book, you will gain extensive hands-on experience installing and configuring a firewall. You will also learn how to allow access to key Web services while maintaining your organization's security, as well as how to implement firewall-to-firewall virtual private networks (VPNs). You will learn how to build a firewall to protect your network; provide access to HTTP and FTP services on the Internet, and implement publicly accessible servers without compromising security. Furthermore, throughout the book, extensive hands-on examples provide you with practical experience in establishing security with firewalls. Examples include, but are not limited to: Installing and configuring Check Point FireWall-1; scanning to validate configuration using ISS Internet Scanner; configuring the firewall to support simple and complex Web services; setting up a packet filtering router; enhancing firewall configurations to support split-DNS; authenticating remote users; and protecting browsers and servers with a proxy-based firewall.
· Install and configure proxy-based and stateful-filtering firewalls
· Protect internal IP addresses with NAT and deploy a secure DNS architecture
· Develop an Internet/intranet security policy to protect your organization's systems and data
· Reduce your susceptibility to an attack by deploying firewalls, data encryption and decryption and other countermeasures
· Install and configure proxy-based and stateful-filtering firewalls
· Protect internal IP addresses with NAT and deploy a secure DNS architecture
· Develop an Internet/intranet security policy to protect your organization's systems and data
· Reduce your susceptibility to an attack by deploying firewalls, data encryption and decryption and other countermeasures
Instant delivery by email
Your access email arrives within minutes of checkout, with a sign-in link for each book — no shipping, no waiting.
Read on any device
Books open in VitalSource Bookshelf on your phone, tablet, or computer, online or offline. Your library is always available at aafaq.vitalsource.com — just log in with the email you used at checkout.
Lost the email?
Resend it to yourself in seconds from My eBook orders, or email cs@aafaqeducation.com and we'll help.