About this interactive
Defense in depth means no single control has to be perfect: if one layer fails, the next one still stands. Securing Your Network builds the layers from the outside in.
- The building: controlled access, equipment off the floor, cooling sized for the room so the temperature stays steady, a UPS and a generator, and devices wiped (their configurations too) before disposal.
- The edge: a firewall whose zones keep public servers in the screened subnet, letting in only returning traffic and what ACL rules allow; an IDS or IPS (an IPS blocks, at the cost of false positives); a next-generation firewall that can block by application.
- Inside: segments for departments, management traffic and IoT, with VLANs; zero trust, so no device is trusted just for being inside, with NAC checking each device's state and port security on the switches; decoys such as a honeypot to catch anyone poking around.
- Wireless and remote access: the highest WPA version with 802.1X; guests kept apart; VPNs, with the split tunnel's trade-off understood; remote desktop through a jump box.
- Every device: hardened to its baseline, the minimum standard for its kind; encrypted drives; no admin rights for everyday accounts; patch management; antivirus and EDR.
About TechKnowSurge
TechKnowSurge builds IT and cybersecurity professionals through hands-on, concept-first training built around real understanding — not memorization. Free interactive tools, structured programs, and 25+ years of real-world experience, all in one place.
Explore free tools and programs →