Protecting Networks: Segmentation · 保护网络:分段
| English | 中文 | Pinyin · 拼音 |
|---|---|---|
| network segmentation/ˈnetwɜːk ˌseɡmənˈteɪʃn/ | 网络分段 | wǎng luò fēn duàn |
| subnets/ˈsʌbnets/ | 子网 | zi wǎng |
| screened subnet/skriːnd ˈsʌbnet/ | 屏蔽子网 | píng bì zi wǎng |
| DMZ/ˌdiː em ˈzed/ | 隔离区 | gé lí qū |
| VLANs/ˈviːlænz/ | 虚拟局域网 | xū nǐ jú yù wǎng |
Divide to contain
- Network segmentation 网络分段 splits one network into isolated subnets 子网.
- If one subnet is breached, the damage is contained.
- It cannot spread to the rest of the network.
分而治之以隔离
- 网络分段(network segmentation)把一个网络拆成隔离的子网(subnets)。
- 如果一个子网被攻破,损害被隔离。
- 它无法扩散到网络的其余部分。
The screened subnet (DMZ)
- A screened subnet 屏蔽子网 (a DMZ 隔离区) sits between the internet and the private network.
- It holds public-facing servers in a lower-security zone.
- This keeps public servers away from sensitive internal systems.
屏蔽子网(DMZ)
- 屏蔽子网(screened subnet)(即DMZ隔离区)位于互联网和私有网络之间。
- 它把面向公众的服务器放在较低安全的区域。
- 这让公共服务器远离敏感的内部系统。
Which network zone? · 哪个网络区域?
The DMZ holds public-facing servers; the private network holds sensitive systems; the internet is untrusted. · DMZ托管面向公众的服务器;私有网络托管敏感系统;互联网是不可信的。
A DMZ (screened subnet) typically holds... · DMZ(屏蔽子网)通常托管……
A DMZ holds public-facing servers. · DMZ 托管面向公众的服务器。
The main security benefit of segmentation is that a breach is... · 分段的主要安全优势在于,一旦遭到入侵,影响范围被……
Segmentation contains a breach. · 分段限制了入侵范围。
Dividing a network into smaller isolated pieces creates . · 将网络划分为更小的独立部分可创建。
Segmentation creates isolated subnets. · 分段创建了独立的子网。
Which are ways to segment a network? (Choose all) · 哪些是网络分段的方式?(多选)
Deleting the firewall reduces security. · 删除防火墙会降低安全性。
Ways to segment
- Subnetting divides by IP address.
- VLANs 虚拟局域网 logically separate devices on the same switch.
- Each segment can have its own security policy.
分段的方式
- 子网划分(subnetting)按IP地址划分。
- VLAN(虚拟局域网)在逻辑上分开同一交换机上的设备。
- 每个分段可以有自己的安全政策。
A flat, unsegmented network is dangerous: once an adversary is inside one device, nothing stops them reaching every other device. Segmentation builds internal walls that contain a breach.
扁平的、未分段的网络很危险:一旦对手进入一台设备,就没有什么能阻止他们到达其他每一台设备。分段建立内部墙壁来隔离入侵。
VLANs can logically separate devices that share the same physical switch. · VLAN可以在逻辑上隔离共享同一物理交换机的设备。
VLANs separate devices logically. · VLAN 在逻辑上分离设备。
A company puts its public web server in a DMZ between two firewalls. If the web server is hacked, the attacker is trapped in the DMZ — the second firewall still stands between them and the private customer database.
一家公司把它的公共网页服务器放在两道防火墙之间的DMZ中。如果网页服务器被黑,攻击者被困在DMZ里——第二道防火墙仍然横在他们和私有客户数据库之间。
Network segmentation divides a network into isolated subnets so a breach stays contained. A screened subnet (DMZ) holds public-facing servers between the internet and the private network. Segment with subnetting or VLANs, each with its own policy.
网络分段把网络分成隔离的子网,使入侵保持被隔离。屏蔽子网(DMZ)把面向公众的服务器置于互联网和私有网络之间。用子网划分或VLAN分段,每个都有自己的政策。