tailieunhanh - ccsp csi exam certification guide phần 9

Bốn tùy chọn thiết kế có sẵn trong mô hình thiết kế mạng người dùng từ xa được thảo luận trong chiều sâu trong phần này. Đối với tất cả bốn lựa chọn, phần mềm quét virus được đề nghị để giảm thiểu mối đe dọa của virus | 290 Chapter 17 Designing Remote SAFE Networks Figure 17-2 Remote-User Design Model Broadband Access Device Authenticate Remote Site Basic Layer 7 Filtering Terminates IPSec VPN Host DoS Mitigation Stateful Packet Filtering Firewall I I with VPN Hub ISP Module Internet Broadband Access Device Broadband Access Device Optional Router with I I Firewall and VPN Authenticate Remote Site Terminates IPSec VPN Hardware Client Hub VPN Software Client with Personal Firewall Authenticate Remote Site Terminates IPSec VPN Personal Firewall and Virus Scanning Software Access Option Remote Site B Site_ .H Firewall Option Broadband Router VPN Client Option Option Design Guidelines for Remote-User Networks The four design options that are available within the remote-user network design model are discussed in depth in this section. For all four options virus-scanning software is recommended to mitigate the threat of viruses and Trojan-horse programs being able to infect the user s PC. Remote-Site Firewall In the remote-site firewall option the design emphasis is on the home-office worker or a small branch office. It is assumed that Internet connectivity is provided via an ISP-supplied broadband access device such as an xDSL or cable modem and that the VPN firewall is located behind this ISP device. Apart from providing connection-state enforcement and detailed filtering for sessions that are initiated through the firewall the firewall also provides secure IPSec connectivity between the firewall device itself and the VPN-enabled headend device. This site-to-site IPSec VPN enables PCs that are located on the remote-site network to access corporate resources without the need of individual VPN software clients. The Cisco VPN Client is discussed in depth in the section Cisco VPN Client later in the chapter. Design Guidelines for Remote-User Networks 291 With a stateful firewall present in the model it is possible for a remote site to have direct Internet access rather than having to rely

TỪ KHÓA LIÊN QUAN