Now in enterprise network's safety precaution measure, the hardware level's firewall as well as from the router end implementation protection is the most main way. However also therefore, many enterprise users in puzzled: The router is the enterprise network essential equipment, oneself has the function not vulgar safety protection function, why can also use the expensive hardware firewall?
Actually this is to these two kind of equipment's in function misunderstanding, the router and the firewall has the respective function key point, from network security's safeguard dynamics, is naturally the hardware firewall is in the upper hand; But regarding the general work network, uses the router to implement the safety protection is also one kind of solution. Below has a look at these two kind of equipment on the distinction the role which can play in the network security.
First, router
The router production is based on produces to a network data package of route. What the router needs to complete is carries on the different network data packet the effective route, as for why route, whether should the route, the route whether to have the question and so on simply not to care from now on; Its primary purpose is maintains the network and the data “passes”.
1. safety protection analysis
In the safe guard aspect, the router default disposition is insufficient to the secure consideration, needs some high-level dispositions to be able to achieve some guard attack the function (for instance router built-in firewall function, domain name filtration function, MAC address filtration function and so on); Security policy's formulation overwhelming majority is based on the command line, it is relatively quite complex in view of the secure rule's formulation, therefore disposes the probability which makes a mistake to be high. (l chart one)

Router safe disposition contact surface
Moreover, disposes some enterprise network when the router the expansion application (for instance disposes when the Internet user may visit internal network resource, needs to turn on corresponding port), also easy to create some safe hidden dangers.
2. is suitable the environment analysis
The router is designed uses for to retransmit the data packet, but is not designs specially takes the complete characteristics firewall, therefore not too suitable to use in the function limits safeguarding the enterprise network the security. Moreover because when enters the luggage filtration, to router CPU and the memory need is big, if also has both the safety protection function, has the possibility gain does not equal the loss, no matter is the route or the safety protection stall. In the ordinary home environment, from the wide band router opening firewall function, then installs the anti-virus software in the computer then to achieve goes by plane safely the goal; But in the enterprise network environment, the router application scope must smaller somewhat, let it concentrate in maintains the network and the data “passes”, is displays its biggest effect the ideal decision.
Other pages: : 1 * 2 * 3 * Next>>
|