15 Download Section
Securepoint 10
Securepoint
Security Solutions
209
15 Zone Concept of the Securepoint Firewall
To every interface of the appliance one zone or several zones are assigned. For example: To
the internal interface the zone
internal
is assigned and to the external interface the zone
external
is assigned.
For the rule set of the firewall, the administrator has to create network objects (IP addresses
or networks) and assign one zone to every network object. This action defines behind which
interface a network object is positioned.
A well known attack scenario on a router is to fake a sender IP address (IP Address Spoof-
ing). If the attacker uses a sender address from the internal network and the packet is send
from a wrong zone (for example: external) the packet will be dropped automatically on the
basis of the zone concept. The administrator doesn’t have to create anti spoofing rules.
Internet
FW zones:
firewall-external;
vpn_ipsec/ vpn-ppp
FW zone:
firewall-DMZ 1
FW zone:
firewall-DMZ 2 - n
FW zone:
firewall-internal
Zone:
DMZ2 to DMZn
Zone:
DMZ1
Zone:
internal
Zone:
external
fig. 222 zone concept of the Securepoint firewall