Network Segmentation Flashcards
1
Q
Segmenting the network
A
- Physical, logical, or virtual segmentation
- Devices, VLANs, virtual networks
• Performance - High-bandwidth applications
- Security
- Users should not talk directly to database servers
- The only applications in the core are SQL and SSH
- Compliance
- Mandated segmentation (PCI compliance)
- Makes change control much easier
2
Q
Physical segmentation
A
- Devices are physically separate
- Switch A and Switch B
- Must be connected to provide communication
- Direct connect, or another switch or router
- Web servers in one rack
- Database servers on another
- Customer A on one switch, customer B on another
- No opportunity for mixing data
- Separate devices
- Multiple units, separate infrastructure
3
Q
DMZ
A
• Demilitarized zone
• An additional layer of security between the Internet
and you
• Public access to public resources