A modern network is more than a router and a switch. Defense in Depth uses different security layers so one failed control does not bring down the entire defense.
Component map
- Switch (L2): VLANs separate traffic; , and reduce unauthorized connections, rogue DHCP and ARP spoofing; authenticates the port.
- Router (L3): an ACL filters by source/destination address and port, but it does not remember connection state or understand application content.
- A load balancer provides availability by distributing traffic; a proxy acts on behalf of LAN clients and enables centralized web policy.
- A VPN server provides site-to-site IPsec or encrypted remote access. A protects layer 7 web applications and inspects HTTP against OWASP Top 10 threats.
- URL filtering, application control, DLP and anti-malware inspect applications and content. combines several capabilities in one appliance — a trade-off between simplicity and depth.
- A mail gateway in the DMZ filters spam and inspects SMTP, reverse DNS and content while keeping the internal mail server hidden.
Practice: topology and CIA
Draw a DC, workstations and a FortiGate. For each component, mark L2/L3/L7, which attack it stops, which it does not, and which part of confidentiality, integrity and availability it supports. For example, blocks an unknown device but not already running inside.
Risks and detection
- “We have a firewall, so we are protected” is a mistake: a perimeter firewall does not necessarily stop internal , or .
- An unconfigured component is not a defense. Verify that , and are enabled, and design VLANs by risk level rather than department alone.
- Only the mail gateway should be exposed in the DMZ; the internal mail server stays hidden.
Mitigation and related topics
- Give every layer a clear role; no single box solves everything.
- Quarterly, verify , VLAN mappings and mail reverse DNS.
- Related topics: , Fortinet detection layers and tiering.