
integrity and the confidentiality of the data coming from the exter-
nal world must be checked and ensured. This feature can be pro-
vided thanks to encryption. To do so, the firewall tunneling solution
must provide VPN capabilities, respecting the IPSec and Internet Key
Exchange (IKE) standards, to ensure the interoperability with other
firewalls or desktop operating systems.
17.6.4 Authentication mechanisms
To have the safest solution, the DMZ must also provide some
authentication mechanism. According to the enterprise organization,
this DMZ can have its own user base or can be integrated with the
enterprise user base, such as a Lightweight Directory ...