Secure Network Architecture
and Network Access Control
The Internet is host to countless information services and numerous applications, including the
Web, email, FTP, Telnet, newsgroups, chat, and so on. The Internet is also home to malicious
people whose primary goal is to locate your computer and extract valuable data from it, use it
to launch further attacks, or damage it in some way. You should be familiar with the Internet
and able to readily identify its benefits and drawbacks from your own online experiences.
(Stewart et al., 2004)
1. Purpose
Because of the success and global use of the Internet, many of its technologies were adapted or
integrated into the private business network. This created two new forms of network segments:
intranets and extranets.
An intranet is a private network that is designed to host the same information services found on
the Internet. Networks that rely upon external servers to provide information services
internally are not considered intranets. Intranets provide users with access to the Web, email,
and other services on internal servers that are not accessible to anyone outside the private
network.
An extranet is a cross between the Internet and an intranet. An extranet is a section of an
organization’s network that has been sectioned off so that it acts as an intranet for the private
network but also serves information to the public Internet. An extranet is often reserved for use
by specific partners or customers. It is rarely on a public network. An extranet for public
consumption is typically labeled a demilitarized zone (DMZ) or perimeter network. (Stewart et al.,
2004)
2. Introduction
Networks are not typically configured as one single large collection of systems. Usually
networks are segmented or subdivided into smaller organizational units. These smaller units,
grouping, segments, or subnetworks (i.e., subnets) can be used to improve various aspects of
the network:
Lebanese National Security Policy Guidelines v1.7
Page
24 |