Safari Books Online is a digital library providing on-demand subscription access to thousands of learning resources.
Firewalls have long provided the first line of defense in network security infrastructures. This is accomplished by comparing corporate policies on network access rights for users to the connection information surrounding each access attempt. User policies and connection information must match. Otherwise, the firewall does not grant access to network resources.
This section examines firewall design considerations. It discusses options for firewall deployment and topologies, including firewall modes, virtual firewalls, asymmetric routing using active/active topologies, scaling firewall performance, private VLANs (PVLAN), and zone-based firewalls.