ZyXEL Communications Centralized Network Management Vantage CNM Manual de usuario Pagina 4

  • Descarga
  • Añadir a mis manuales
  • Imprimir
  • Pagina
    / 6
  • Tabla de contenidos
  • MARCADORES
  • Valorado. / 5. Basado en revisión del cliente
Vista de pagina 3
Perimeter
Protection
mySecurity zone
myZyXEL.com
Services Platform
Headquarters
ZyWALL Internet
Security Gateway
ZyWALL IDP
ZyWALL
ZyWALL
Branch Office
Internet
Site-to-Site
VPN
Personal
Protection
(Remote Access)
Mobile Users
ZyWALL Personal
Firewall/VPN
Web, Mail
Server
ZyWALL Internet
Security Gateway
Managed
Ethernet Switch
Vantage CNM
Centralized network
management
Server Farm
ZyWALL
Personal
Firewall
Workgroup
Workgroup
Protection
Personal
Protection
Perimeter Protection Workgroup Protection
ZyXEL's ZyWALL series of firewalls is suitable for
deployment at the entrance to the corporate and SMB
networks, undertaking the duty of perimeter gateway
protection.
The benefit of deploying information security systems on
the gateway is that they act a single point of access to the
corporate network and the main access point to the
Internet. The system can thus monitor all the incoming
and outgoing traffic, and grant or deny incoming data
passage in accordance with company's network security
policies. Under the gateway-deployed security structure,
the deployed gateway will take charge of corporate LAN
security, and replace complicated individual client security
schemes.
The disadvantage of using a gateway-deployed security
system alone is that it also is a single point-of-failure risk.
Once the attack is past the gateway, it has complete
access to the LAN. This is why ZyXEL advocates a multi-
layer approach.
In the case where worms or other attacks have
successfully penetrated into the corporate network, the
top priority is isolating the infection to prevent it from
spreading and causing more damage. This requires the
workgroup-level security offered by ZyWALL devices. With
this security feature activated, even if a few departments
have been invaded by a worm or have already suffered an
attack, the damage can be contained within the affected
workgroups without jeopardizing others, thanks to
ZyWALLs excellent Workgroup Protection capabilities.
This function acts by disconnecting an infected
workgroup from the LAN. While the infected workgroup
will temporarily lose connection with the other
departments, all the company's remaining IT assets will
remain intact. Other nodes, small offices, and remote
offices added for business expansion may become the
source of security threats if not controlled properly. For
more security, intrawall-security will become essential
between workgroups.
5
6
Remote Access Security
As telecommuting is becoming a more accepted and
practiced work medium, more people need to connect to
corporate networks for online resources, and a remote
access VPN feature is indispensable for this purpose.
To facilitate both telecommuting and mobile computing,
and to meet the market's needs, ZyXEL offers the ZyWALL
portable personal firewall in addition to its Remote VPN
Security Client which provides an alterative security
solution to users who connect to the office over the
public Internet or use an un-trusted connection from
public hotspots or a home network.
Internet and affordable broadband connections equipped
with secure and private communications. Site-to-site VPN
technology benefits from the ZyXEL Vantage CNM, the
Centralized network management mechanism, since it
simplifies VPN setup, management and monitoring of
multi-site IPSec VPN tunnels. Users can easily set up a VPN
with a few steps, while at the same time, reducing the on
going management complexity.
Personal Protection
Even with gateway and workgroup protection in place,
threats from inside the LAN are still a major concern.
Infected files can easily be brought into the office by
traveling employees, and spread within the workgroup as
he or she passes the file to colleagues. Individual clients
may consider using personal firewall devices to reinforce
their protection. The portability of the device helps users
prevent attackers from accessing private or public
networks. As a best-of-breed portable personal firewall, the
ZyWALL Personal Firewall appliance can effectively defend
individual systems in collaboration with gateways and
departmental protections.
Site-to-Site VPN
Apart from multi-level protection against internal and
external threats, the ZyWALL ICSA-certified IPSec VPN can
also provide users cost effective site-to-site VPN
applications, allowing users to take advantage of the
ZyXEL SMART Network Security Blueprint for SMB
Vista de pagina 3
1 2 3 4 5 6

Comentarios a estos manuales

Sin comentarios