Cisco Cisco FirePOWER Appliance 8350 Guida All'Installazione

Pagina di 238
 
2-17
FireSIGHT System Installation Guide
 
Chapter 2      Understanding Deployment
  Using a Multi-Port Managed Device
Although this segment must be readily available for your business to function, it must be tightly 
restricted controlled. Access control should ensure that these assets cannot be reached by those network 
segments with the highest risk, such as remote networks or mobile devices. Always use the most 
aggressive control on this segment, with strict rules for user and application access. 
On a Remote or Mobile Network
Remote networks, located off-site, often use a virtual private network (VPN) to provide access to the 
primary network. Mobile devices and the use of personal devices for business purposes (for example, 
using a “smart phone” to access corporate email) are becoming increasingly common. 
These networks can be highly dynamic environments with rapid and continual change. Deploying a 
managed device on a dedicated mobile or remote network allows you to create a strict access control 
policy to monitor and manage traffic to and from unknown external sources. Your policy can reduce your 
risk by rigidly limiting how users, network, and applications access core resources.
Using a Multi-Port Managed Device
The managed device offers multiple sensing ports on its network modules. You can use the multi-port 
managed devices to: