Designing and Building Enterprise DMZs
暫譯: 設計與建構企業 DMZ

Hal Flynn

  • 出版商: Syngress Media
  • 出版日期: 2006-12-06
  • 售價: $2,460
  • 貴賓價: 9.5$2,337
  • 語言: 英文
  • 頁數: 737
  • 裝訂: Paperback
  • ISBN: 1597491004
  • ISBN-13: 9781597491006
  • 已過版

買這商品的人也買了...

相關主題

商品描述

Description 

Some of the most complicated areas of network technology are designing, planning, implementing, and constantly maintaining a demilitarized zone (DMZ) segment. In this book, readers will learn the concepts and major design principles of all DMZs. Next, readers will learn how to configure the actual hardware that makes up DMZs for both newly constructed and existing networks. Then they will learn how to securely populate the DMZs with systems and services. The final section of the book deals with troubleshooting, maintaining, testing, and implementing security on the DMZ.

·        Plan Your Network Security
Understand DMZ concepts, layout, and conceptual design.

·        Build a Windows DMZ
Use the check list to start your Windows DMZ implementation by covering network engineering, systems engineering, and security analysis.

·        Learn Sun Solaris DMZ Design
Determine what software is required to provide DMZ services with a Solaris system, including Check Point FireWall-1 and SunScreen Secure Net.

·        Build a Wireless DMZ
Understand how, with a bit of creativity, you can implement a WLAN DMZ using RADIUS, Cisco LEAP, or PEAP.

·          Review Cisco PIX and ASA Versions and Features
Secure network perimeters using PIX/ASA.

·        Use Check Point to Secure Your Network Perimeter
Use SmartDefense to protect your network from multiple types of attacks, including DoS attacks.

·        Review the Features of Juniper NetScreen
NetScreen has a variety of options to implement: deep inspection (DI) technology, SecureOS, and features such as Web filtering and antivirus scanning.

·          Configure ISA 2004 as an Enterprise Network Services Segment Perimeter Firewall
See how the ISA firewall can act in a number of roles: a front-end edge firewall that sits in front of a whole company or as a back-end firewall located behind another edge firewall.

·        Secure the Router and Switch
Don’t overlook hardening the routers or switches supporting the DMZ.

·        Review DMZ-Based VPN Services
See how VPN services in the DMZ can be designed to provide connectivity to two primary groups of users: business partners and remote users.

·        Configure Bastion Hosts
See how to configure your bastion host as a Web server.

商品描述(中文翻譯)

一些網路技術中最複雜的領域是設計、規劃、實施和不斷維護非軍事區(DMZ)區段。在本書中,讀者將學習所有 DMZ 的概念和主要設計原則。接下來,讀者將學習如何配置構成 DMZ 的實際硬體,無論是新建的還是現有的網路。然後,他們將學習如何安全地填充 DMZ 的系統和服務。本書的最後一部分將處理 DMZ 的故障排除、維護、測試和安全實施。

· 計劃您的網路安全
了解 DMZ 概念、佈局和概念設計。

· 建立 Windows DMZ
使用檢查清單開始您的 Windows DMZ 實施,涵蓋網路工程、系統工程和安全分析。

· 學習 Sun Solaris DMZ 設計
確定提供 DMZ 服務所需的軟體,包括 Check Point FireWall-1 和 SunScreen Secure Net。

· 建立無線 DMZ
了解如何利用一些創意,使用 RADIUS、Cisco LEAP 或 PEAP 實施 WLAN DMZ。

· 檢視 Cisco PIX 和 ASA 版本及功能
使用 PIX/ASA 來保護網路邊界。

· 使用 Check Point 來保護您的網路邊界
使用 SmartDefense 來保護您的網路免受多種攻擊,包括 DoS 攻擊。

· 檢視 Juniper NetScreen 的功能
NetScreen 提供多種選項來實施:深度檢查(DI)技術、SecureOS,以及網頁過濾和防病毒掃描等功能。

· 將 ISA 2004 配置為企業網路服務段邊界防火牆
了解 ISA 防火牆如何在多種角色中運作:作為整個公司的前端邊界防火牆或作為位於另一個邊界防火牆後面的後端防火牆。

· 確保路由器和交換機的安全
不要忽視加固支援 DMZ 的路由器或交換機。

· 檢視基於 DMZ 的 VPN 服務
了解 DMZ 中的 VPN 服務如何設計以提供兩個主要用戶群的連接:商業夥伴和遠端用戶。

· 配置堡壘主機
了解如何將您的堡壘主機配置為網頁伺服器。