
YuChakTinMichael‘sGIACGCFWProjectAssignment
Page 11
q SSLanddigitalcertificatesaredeployedbytheecommercewebsite.Such
capabilitiesarebuiltintothewebserver.
q TwosetsofDNSsystemsareinplace,oneforexternaluseandoneforinternal
use.Thisisknownas“DNSSplitHorizon”.
q TwosetsofSMTPmessagingsystemsareinplace,oneforexternaluseandone
forinternaluse.
q AllserversareMicrosoftWindowsbased.
q TheEcommercewebapplicationisupdatedbytheinternalwebdevelopersvia
standardprotocol(HTTP/HTTPS)basedmethod,suchasFrontPageServer
extension.MicrosoftNetworkingisnotinvolvedintheupdateactivities.
B2B:
B2BisaboutthesecurecommunicationprocessbetweenGIACanditsexternal
partners&suppliers.Sincethecommunicationmediumistheinternet,VPN
technology isused. Thedatabaseapplicationserverallowsaccessviaastandard
HTTP/HTTPSinterfaceforeaseofcontrolandadministration.
RegardingtheVPNmodel,aroutertorouterVPNmodelisnotdeployedprimarily
becausethevolumeofusebetweenthepartneringorganizationsdoesnotjustifya
fixedroutertoroutersetup.Instead,a RemoteAccessPPPbasedVPNsolutionis
deployedtogiveflexibilityandsimplerconfiguration.Forthisreason,incomingVPN
trafficistobeprocessedbyaVPNserverwhileoutgoingtrafficisnot(outgoingVPN
connectionstoexternalpartnersareconfiguredontheclientsideforuserswhoneed
suchaccess.NoserversidesettingisinvolvedinGIACnetworkforoutboundVPN
requests).
B2Btrafficincludesrequestsforthefollowing:
à RemoteaccessviaVPNfromtheexternalpartnersandsupplierstothe
databaseapplicationserver.Forsecurityandeaseofcontrol/administration,
astandardizedwebbasedinterfaceisused.Forthistowork, TCPport80
mustbeused.
INET:
INET trafficaccommodatesoutboundrequestsforthefollowing:
à Internalstaffsaccessingtheinternet:HTTP,HTTPS,FTP,SMTP
Komentarze do niniejszej Instrukcji