
YuChakTinMichael‘sGIACGCFWProjectAssignment
Page 19
n RoutingandtrafficinspectionareCPUintensive.Dualprocessorsystemis
alwaysrecommended. Althoughmanyrouter/firewallproductsdonotmakeuse
ofSMP(SymmetricMultiprocessing,acomputerarchitecturethatmakes
multipleCPUsavailabletocompleteindividualprocessessimultaneously),the
operatingsystems(WindowsNT,Windows2000,Linux…etc) themselvescan
assignoneprocessortospecializeinhandlingtheOSstuff,thusfreeinganother
processortoperformroutingor trafficinspection.
n ItisalwaystruethatmoreRAMisbeneficial.WhenusingWindows2000Server
astheOS,128MBRAMisthebasicminimum,while256MBRAMisthe
preferredbaseline.Windows2000Professionalisgenerallylessdemanding.
n RAID1diskmirrorshouldbeusedforredundancy.WindowsNTandWindows
2000(aswellasmanyLinux/Unixdistributions)supportsRAID1natively
withouttheneedtopurchaseadditionalhardware.ThegoodthingaboutRAID1
isthatitcanprotecttheOSitself,whileRAID5cannot(Iamtalkingabout
softwareRAID5here).
n Reservesufficientdrivespacetoaccommodatethelogs.Theselogsaretobe
backedupregularly justincasefurtheranalysisisrequired.
n Goodquality 100BaseTNICsfromreputablemanufacturers(such as3COMand
Intel)areused.Thesecardsarerelatively stableand troublefreeintermsof
installationandcompatibility.
ListofEquipments:
BelowisalistofrouterandfirewallequipmentsusedintheGIACnetwork.The
networkdiagramdoesnotrepresentthe“physicallocations”oftheseequipments.In
fact,aproperlysecuredandclimatecontrolledserverroomshouldbeassignedfor
hostingtheseequipments.Physicalsecurityisasimportantaslogicalsecurity inthe
realworld.
Comentarios a estos manuales