Академический Документы
Профессиональный Документы
Культура Документы
1.Firewall
2.DMZs
DMZ (demilitarized zone)
DMZ (demilitarized zone) is a physical or logical sub-
network that separates an internal local area network
(LAN) from other untrusted networks, usually the
Internet.
External-facing servers, resources and services are located
in the DMZ so they are accessible from the Internet but
the rest of the internal LAN remains unreachable.
This provides an additional layer of security to the LAN as
it restricts the ability of hackers to directly access internal
servers and data via the Internet.
DMZ Operation
Hierarchical Network Design
1. Core Layer Design
The core layer is a high-speed
switching backbone and should be
designed to switch packets as fast
as possible.
This layer of the network should
not perform any packet
manipulation, such as access lists
and filtering, that would slow down
the switching of packets
Technology used at Core Layer
1. Multilayer Switches
A multilayer switch is a
network device that has
the ability to operate at
higher layers of the OSI
reference model.
A multilayer switch can
perform the functions of a
switch as well as that of a
router at incredibly fast
speeds.
2. Redundancy and Load Balancing
Redundancy is a system design in which a
component is duplicated so if it fails there will be
a backup.
Redundancy has a negative implication when the
duplication is unnecessary or is simply the result
of poor planning.
Network load balancing (commonly referred to as
dual-WAN routing or multihoming) is the ability
to balance traffic across two WAN links without
using complex routing protocols like BGP.
3. High Speed and Link
Aggregation
(EtherChannel)
Take many links, bundle
them into a single logical
link.
Provides High Speed Link
Link aggregation (collection) provides the
following benefits:
I. Logical aggregation of bandwidth
II. Load balancing
III. Fault tolerance
4. Routing protocols
Implementation between router
These protocols have been designed to allow the
exchange of routing tables, or known networks,
between routers.
Marking & prioritizing traffic