CHAPTER 2: Installing a Firebox Vclass Security Appliance
22
Vcontroller 3.2
to interface
1
. Any public-to-private access would then be strictly
controlled by the appliance.
Protecting the whole network from external access
You may want to protect your entire network from unauthorized users or
from attack, as shown in the following illustration.
In this scenario, the entire network is the primary resource, utilizing the
Firebox Vclass appliance as protection. You would then place the
appliance so that the Internet connection is to interface 1 (representing the
outside), and the internal network connection is to interface 0
(representing the inside).
Establishing load balancing for heavily used network assets
As an alternate firewall option, you may want to place the Firebox Vclass
appliance so that it directs external data requests to a cluster of Web
servers that ideally would be utilized by both internal and external users.
At the same time, you may also want to establish a firewall that facilitates
access to those servers by external users while protecting the rest of the
network from those external users.
In this scenario, all external connections would be channelled through
interface 1. The appliance can be placed so that the primary asset would
be the internal network connected to interface 0. This asset is inside the
appliance’s sphere of influence. Everything else is effectively outside.
1install_guide.book Page 22 Friday, June 7, 2002 1:10 PM