Network Security Layers
Standard security management practice is to test security to confirm proper configuration, performance, and strength against attacks and exploits. When a firewall is updated or its settings modified, another round of firewall testing should be conducted.
Some approaches to firewall testing that do not disrupt the production environment are:
Simulated firewall tests: Use an attack simulator to transmit attack packets to the firewall
Virtual firewall tests: Are performed in a virtualized network environment using a virtualization tool
Laboratory tests: Are run in nonproduction subnets on a duplicate of the production environment
Answer the following question(s):
Which approach do you think would be most effective? Why?
Sample Answer
The most effective approach to firewall testing that does not disrupt the production environment is laboratory tests. This is because laboratory tests allow you to replicate the production environment as closely as possible, which means that you can be more confident that the results of the test are accurate.
Simulated firewall tests and virtual firewall tests are not as effective because they do not allow you to replicate the production environment as closely. Simulated firewall tests use an attack simulator to transmit attack packets to the firewall, but this does not take into account the way that the firewall is configured or the way that the production environment is used. Virtual firewall tests are performed in a virtualized network environment, but this environment may not be as secure as the production environment.