• Do not solely rely on IDS/IPS to protect the network. IDS/IPS are only real-time detection tools to alert users on abnormal or suspicious activities. More importantly, the network should be properly configured with all necessary security protection mechanisms. The whole network should be closely monitored and regularly reviewed so that security loopholes or misconfiguration can be identified promptly.
Firewalls
Depending on the security requirements, the use of two or more firewalls or routers in serial helps to provide an additional level of defence.
ファイアウォール
セキュリティ要件に応じて、連続して2つ以上のファイアウォールやルータの使用することで、防御レベルを上げることになる。
ファイアウォール
セキュリティの必要条件に応じた、続き番号の二つ以上のファイアウォールやルータの使用は、防御のレベル・アップをもたらすのに役立ちます。
For example, two firewalls in serial (one internally connected with the internal router and one externally connected with the external router) may be required to provide different protections. If there is one RAS connected to the DMZ and placed between the internal and external firewall, the external firewall may aim at blocking malicious traffic from the Internet while the internal one may aim at blocking malicious traffic from the internal network users and the remote access users connected to RAS. If multiple firewalls are used in parallel for load balancing or performance reasons, the configuration of each firewall should be aligned.
Great!