Boosting performance Network segmentation can improve performance through an organizational scheme in which systems that often communicate are located in the same segment while systems that rarely or never communicate are located in other segments. Reducing communication problems Network segmentation often reduces congestion and contains communication problems, such as broadcast storms, to individual subsections of the network. Providing security Network segmentation can also improve security by isolating traffic and user access to those segments where they are authorized. Segments can be created by using switch-based VLANs, routers, or firewalls, individually or in combination. A private LAN or intranet, a DMZ, and an extranet are all types of network segments. When you’re designing a secure network (whether a private network, an intranet, or an extranet), you must evaluate numerous networking devices. Not all of these components a re necessary for a secure network, but they are all common network devices that may have an impact on network security. (Stewart et al., 2004) 3. Network and Protocol Security Mechanisms TCP/IP is the primary protocol suite used on most networks and on the Internet. It is a robust protocol suite, but it has numerous security deficiencies. In an effort to improve the security of TCP/IP, many sub-protocols, mechanisms, or applications have been developed to protect the confidentiality, integrity, and availability of transmitted data. It is important to remember that even with the foundational protocol suite of TCP/IP; there are literally hundreds, if not thousands, of individual protocols, mechanisms, and applications in use across the Internet. Some of them are designed to provide security services. Some protect integrity, others protect confidentiality, and others provide authentication and access control. (Stewart et al., 2004) 4. Network Access Control Controlling network access is to prevent unauthorized access to networked services. Access to both internal and external networked services should be controlled. User access to networks and network services should not compromise the security of the network services by ensuring: a) appropriate interfaces are in place between the organization’s network and networks owned by other organizations, and public networks; b) appropriate authentication mechanisms are applied for users and equipment; c) control of user access to information services is enforced. Lebanese National Security Policy Guidelines v1.7 Page 25 |

Select target paragraph3