sistemi-e-reti firewall DMZ ACL VPN GDPR NIS2 security exam

Local Network Design — Part 3: Security and Regulations

Reference guide for the Networks & Systems written exam — part three. Covers perimeter security, access control and European regulatory requirements.


9. Network Security

Firewall and DMZ

The Firewall is the fundamental component for perimeter defence: it filters inbound and outbound traffic according to rules defined by the administrator. It can operate at different levels:

TypeOSI LayerCharacteristics
Packet FilterL3Analyses IP and TCP/UDP headers (addresses and ports). Fast but does not inspect the payload.
Stateful InspectionL4Tracks active sessions: automatically allows return traffic for already-authorised connections.
Application Layer Gateway / NGFWL7Inspects application-layer content (HTTP, DNS, TLS). Next Generation Firewalls integrate IDS/IPS, antivirus and application control.

The DMZ (DeMilitarized Zone) is an intermediate network, separated from both the Internet and the internal LAN, where publicly accessible servers (web server, mail server, VPN server) are placed. If a server in the DMZ is compromised, the attacker does not have direct access to the internal network.

Architecturally it is implemented with:

  • Two firewalls (more secure): one between the Internet and DMZ, one between the DMZ and LAN.
  • A single three-interface firewall (WAN, LAN, DMZ): more economical and common in SMEs.

Access Control Lists (ACL)

ACLs are rule lists configured on routers and Layer 3 switches to filter traffic based on source/destination IP addresses and port numbers.

TypeCisco NumberingFilterPlacement
Standard1–99Source IP onlyAs close as possible to the destination
Extended100–199Source IP, destination IP, protocol, portAs close as possible to the source

Every ACL ends with an implicit deny any any: everything not explicitly permitted is blocked.

Exam tip: Example of an extended ACL rule:

permit tcp 192.168.10.0/26 any eq 443

Allows HTTPS traffic generated by the Administration VLAN to any destination. Always justify the ACL placement (in/out, on which interface).

VPN — Secure Remote Access

A VPN (Virtual Private Network) creates an encrypted tunnel over a public network (Internet), allowing secure access to corporate resources from remote locations.

TechnologyTypeCharacteristics
IPsecSite-to-SiteConnects two company sites transparently to users. The tunnel is always active; packets are encrypted between the two routers/firewalls.
SSL/TLS VPNClient-to-SiteAllows individual remote users (e.g. remote working) to connect via a VPN client. Uses TCP port 443, often not blocked by public firewalls.
WireGuardClient-to-SiteModern, lightweight and very high-performance protocol; an emerging alternative to IPsec.

10. IT Security Regulations

A network design must comply with current European regulations. Mentioning them in an exam demonstrates design maturity.

GDPR — EU Regulation 2016/679

Protects privacy and personal data. The main design implications are:

  • Privacy by Design approach: data protection must be built in from the design phase, not added afterwards.
  • Mandatory use of encryption (e.g. AES, TLS) for sensitive data in transit and at rest.
  • Network segmentation via VLANs to isolate personal data from general traffic.
  • Strict procedures in case of Data Breach: notification within 72 hours to the national Data Protection Authority.

NIS 2 Directive — EU 2022/2555

Applies to critical infrastructures and essential entities (healthcare, transport, energy, public administration). It mandates:

  • Business Continuity: ensuring operational continuity even when incidents occur.
  • Disaster Recovery: documented plans for restoring systems after a major outage.
  • Supply Chain Security: verifying that suppliers and partners meet adequate security standards.
  • Rapid incident reporting to the national CSIRT.

Technical Solution → Regulation Mapping

Technical SolutionSupported Regulation
VLAN segmentation for sensitive dataGDPR (Privacy by Design)
TLS encryption on network trafficGDPR, NIS 2
IPsec VPN for remote accessGDPR, NIS 2
ISP failover + Disaster Recovery planNIS 2 (Business Continuity)
Firewall + IDS/IPSNIS 2 (risk management)

Exam tip: If the scenario involves a public administration, a school or a healthcare facility, always cite NIS 2 and GDPR as regulatory constraints of the project. Mentioning that VLAN segmentation and traffic encryption (TLS, IPsec VPN) are technical tools that contribute to regulatory compliance demonstrates design maturity.