Management of Information Security, Fourth Edition 10-6
4. Describe how a demilitarized zone (DMZ) functions to provide a less restricted area for
the placement of servers that service requests from outside untrusted networks, while
separating them from internal networks.
5. Define a cache server as a server that stores the most recently accessed information
within an internal cache, for quick access.
9. Note the disadvantage a stateful firewall has when under extreme load, such as from a
denial of service attack.
10. Introduce the dynamic packet filtering firewall, which allows only a particular packet
with a specific source, destination, and port address to pass through a firewall.
Firewall Architectures
1. Explain that each of the firewall generations can be implemented in a number of
architectural configurations, and point out that the configuration used can be dependent
on different organizational specific factors.
6. Define how Network Address Translation (NAT) is used to allow private IP networks
to communicate using an external IP address, typically on a one-to-one basis.
7. Port Address Translation (PAT) should be compared to NAT. Note that PAT allows a
single public IP address to be used by many private IP addresses, through the use of
address and port (or socket) combinations.
8. Discuss the three different private IP network ranges: