Local Network Design — Part 3: Security and Regulations
Reference guide for the Networks & Systems written exam — part three. Covers perimeter security, access control and European regulatory requirements.
9. Network Security
Firewall and DMZ
The Firewall is the fundamental component for perimeter defence: it filters inbound and outbound traffic according to rules defined by the administrator. It can operate at different levels:
| Type | OSI Layer | Characteristics |
|---|---|---|
| Packet Filter | L3 | Analyses IP and TCP/UDP headers (addresses and ports). Fast but does not inspect the payload. |
| Stateful Inspection | L4 | Tracks active sessions: automatically allows return traffic for already-authorised connections. |
| Application Layer Gateway / NGFW | L7 | Inspects application-layer content (HTTP, DNS, TLS). Next Generation Firewalls integrate IDS/IPS, antivirus and application control. |
The DMZ (DeMilitarized Zone) is an intermediate network, separated from both the Internet and the internal LAN, where publicly accessible servers (web server, mail server, VPN server) are placed. If a server in the DMZ is compromised, the attacker does not have direct access to the internal network.
Architecturally it is implemented with:
- Two firewalls (more secure): one between the Internet and DMZ, one between the DMZ and LAN.
- A single three-interface firewall (WAN, LAN, DMZ): more economical and common in SMEs.
Access Control Lists (ACL)
ACLs are rule lists configured on routers and Layer 3 switches to filter traffic based on source/destination IP addresses and port numbers.
| Type | Cisco Numbering | Filter | Placement |
|---|---|---|---|
| Standard | 1–99 | Source IP only | As close as possible to the destination |
| Extended | 100–199 | Source IP, destination IP, protocol, port | As close as possible to the source |
Every ACL ends with an implicit deny any any: everything not explicitly permitted is blocked.
Exam tip: Example of an extended ACL rule:
permit tcp 192.168.10.0/26 any eq 443Allows HTTPS traffic generated by the Administration VLAN to any destination. Always justify the ACL placement (in/out, on which interface).
VPN — Secure Remote Access
A VPN (Virtual Private Network) creates an encrypted tunnel over a public network (Internet), allowing secure access to corporate resources from remote locations.
| Technology | Type | Characteristics |
|---|---|---|
| IPsec | Site-to-Site | Connects two company sites transparently to users. The tunnel is always active; packets are encrypted between the two routers/firewalls. |
| SSL/TLS VPN | Client-to-Site | Allows individual remote users (e.g. remote working) to connect via a VPN client. Uses TCP port 443, often not blocked by public firewalls. |
| WireGuard | Client-to-Site | Modern, lightweight and very high-performance protocol; an emerging alternative to IPsec. |
10. IT Security Regulations
A network design must comply with current European regulations. Mentioning them in an exam demonstrates design maturity.
GDPR — EU Regulation 2016/679
Protects privacy and personal data. The main design implications are:
- Privacy by Design approach: data protection must be built in from the design phase, not added afterwards.
- Mandatory use of encryption (e.g. AES, TLS) for sensitive data in transit and at rest.
- Network segmentation via VLANs to isolate personal data from general traffic.
- Strict procedures in case of Data Breach: notification within 72 hours to the national Data Protection Authority.
NIS 2 Directive — EU 2022/2555
Applies to critical infrastructures and essential entities (healthcare, transport, energy, public administration). It mandates:
- Business Continuity: ensuring operational continuity even when incidents occur.
- Disaster Recovery: documented plans for restoring systems after a major outage.
- Supply Chain Security: verifying that suppliers and partners meet adequate security standards.
- Rapid incident reporting to the national CSIRT.
Technical Solution → Regulation Mapping
| Technical Solution | Supported Regulation |
|---|---|
| VLAN segmentation for sensitive data | GDPR (Privacy by Design) |
| TLS encryption on network traffic | GDPR, NIS 2 |
| IPsec VPN for remote access | GDPR, NIS 2 |
| ISP failover + Disaster Recovery plan | NIS 2 (Business Continuity) |
| Firewall + IDS/IPS | NIS 2 (risk management) |
Exam tip: If the scenario involves a public administration, a school or a healthcare facility, always cite NIS 2 and GDPR as regulatory constraints of the project. Mentioning that VLAN segmentation and traffic encryption (TLS, IPsec VPN) are technical tools that contribute to regulatory compliance demonstrates design maturity.
EC