Network security components – RADIUS/TACACS+, FWs, IDS/IPSs, NAC, and WAFs
In this section, we will provide short descriptions of various network security devices and their functionality.
Firewalls
Firewalls provide the following features:
- Packet filtering forwards or drops sessions based on Layer 3 and Layer 4 information. This mechanism is the easiest one to break.
- Network Address Translation (NAT) is used to translate outgoing packets from internal to external internet addresses. This mechanism provides security as a side effect but is not considered to be a security mechanism.
- Stateful inspection watches the directions of TCP connections or UDP sessions that are opened through it, not only the Layer 3 and Layer 4 information. This method provides more security for the firewall.
In addition to this, most modern firewalls can provide additional mechanisms, depending on licensing:
- Intrusion detection and prevention (IDPS): This can discover...