The Enterasys Professional Services organization can perform a thorough analysis
of the rules deployed for Internet-facing firewalls, verifying compliance with
your acceptable usage policies and identifying potential security threats caused
by vulnerabilities with the existing firewall setup. In addition, we can analyze
firewall traffic flows to ensure that they are going through the proper authorization
process based on the defined rule set.
Our engineers will leverage the traffic flow collection and classification
capabilities of Enterasys’ Dragon® Network Defense solution to perform
the audit. This service is designed to optimize the performance and security
of an enterprise’s current firewall solution—the critical first
line of defense between an organization and outside threats.
Enterasys Professional Service representatives and our certified partners
are network design and troubleshooting experts who will work directly with
your network IT specialists to conduct the firewall audit service and determine
the next appropriate steps, if necessary.
- Meet with enterprise security personnel to understand the current network
usage policies and to define specific goals related to the firewall audit
- Detail the firewall hardware and status of the current software version;
report on any known security threats or vulnerabilities
- Perform a security analysis and review of the deployed firewall rule set,
verifying that policies are accurately enforced and identifying any potential
security vulnerabilities
- Deploy Dragon Network Defense on the firewall networks; provide remote
management access to Enterasys Professional Services
- Collect and analyze traffic flows at each of the determined monitoring
points, verifying the deployed rule set is correctly being implemented and
enforced by the firewall
- Perform non-threatening and low-bandwidth penetration testing on the deployed
firewall to provide a wider application profile
- Provide final report detailing firewall software revisions, potential security
vulnerabilities, policy violations and all recommended firewall rule alterations
necessary to circumvent security vulnerabilities and violations
- Thorough evaluation of existing firewall solution identifies known security
vulnerabilities and recommends steps to further strengthen enterprise perimeter
security
- Review and analysis to detect simple, yet harmful configuration deficiencies
that otherwise expose the network to undesirable behavior and security risks
- Analyzes traffic flows traversing the enterprise firewall and tests how
applications penetrate the firewall to help identify additional vulnerabilities
- Brings added assurance in the following instances: there’s been a
change in firewall administration, numerous policies have been implemented
over time, or new usages rules have been recently updated
|