Search Helium

Home > Computers & Technology > Hardware > Networking & IT Management

Best practices for network security in small and medium-size businesses

by Dave Stanford

Created on: June 09, 2009   Last Updated: July 20, 2010

Network security is the most important part of any network today, whether it be a small home (SOHO) network or a large corporate network (LAN or WAN). It is vital to protect network resources whether they are files, emails, or any other information that is stored or passed through the network. A breach of security can often cause both personal and business loss, so it is more important than ever to secure a network.

The first step in securing your network is to first determine the elements that comprise your network and which of these elements are most important to protect. These elements can be routers, switches, servers, or even local user PC's or laptops. Once you determine what makes up your network topology you can then determine the key starting points and what you will need to do to secure each element.

Routers are often on the outside of a network and permit traffic such as email and internet/server access, to enter and exit the local network. It is important that only permitted traffic enter or exit the network and this can be accomplished in a few methods.

1) Access-lists can be configured on the router which permits certain traffic to enter or leave the device and the network. If traffic matches permitted access-lists then it will be allowed to flow. If there is no match or if it is denied then this traffic will be dropped. If logging is configured on the device an alert can also be sent to notify a network management system (NMS) that the deny occurred.

2) Access-lists will not catch everything so it is also useful to include a firewall in the topology. There are numerous models of firewalls available, whether they are hardware or software based, and they add an extra layer of security to the network. They are aware of certain patterns and traffic signatures and prevent users (inside or outside) from using loopholes in access-lists to get into your network.

Firewalls should be placed just inside of the network border router so that it inspect all traffic that makes it to or from the router and catches anything that should be allowed to be sent. One of the most popular types of firewalls on the market today is the Cisco PIX or the newer model ASA. These come in all types and support different size networks.

Switches are very similar to routers and can also use access-lists or policies to prevent unauthorized access. They can also use MAC address (hardware address) filtering to prevent users from connecting to the network. Some software allows end

Helium Debate

Cast your vote!

Which computer is best for the music-minded: Mac or PC?

Click for your side.

262864

Featured Partner

Lazarus House

Lazarus House, Inc. is a spiritually based organization that welcomes all in the name of God. It provides a continuum of care encompassing, but not limited to food, shelter, clothing, advocacy, job training, medical and dental care, a li...more


CONNECT WITH US

Read
our blog
Helum for writers

Write and get published
Share with other writers
Polish your freelancing skills

Join our active writing community
Helium Content Source for Publishers

Quality articles from proven freelancers
Exclusive rights, fast turnaround
Brand engagement, business blogging -- our writers do it all

Get custom content today!

INFORMATION


Helium, Inc.
200 Brickstone Square Andover, MA 01810 USA
#