94
W&T
Security & Maintenanceh
11�1 Security notes
The following sections contain information and recommenda-
tions relevant from an IT security perspective for commissio-
ning, configuring, operating and maintaining the Microwall.
11�1�1 Function and typical use
The Microwall is a strictly whitelist-based small firewall desi-
gned as an IPv4 router with two Ethernet ports and an integ-
rated WireGuard VPN access, which can be used either as a
client (outgoing) or as a server (incoming).
The typical application is to logically decouple a network
island from a higher-level intranet. It thus supports the opera-
tor in segmenting the network as a basic measure of many IT
security concepts. The intranet side of the microwall (
Network
1, yellow
) can be connected to the Internet via additional rou-
ters and perimeter firewalls. From the perspective of a defen-
se-in-depth strategy, the microwall is therefore always deplo-
yed behind at least one perimeter firewall and outside a DMZ.
For the purpose of remote maintenance, the Microwall has a
WireGuard VPN endpoint on the intranet side (
Network 1, yel-
low
). As a client or server, this enables encrypted, authentica-
ted remote access to subscribers in the island network, which
is protected by its own firewall. Cross-access to the intranet at
the Network 1 port via the VPN is not possible.
11�1�2 Requirements for integrators and operators
The factory settings of the Microwall are oriented towards
a universal and preferably barrier-free initial start-up in an
intranet.
Depending on the individual network environment and the
security requirements, these specifications must be checked
for operational use. Changes and/or additional measures may
be required by the integrator or operator. These include in
particular:
Summary of Contents for 55211
Page 6: ...W T ...
Page 7: ...7 W T Subject to error and alteration 1 Legal information and safety ...
Page 12: ...12 W T ...
Page 56: ...56 W T Operation modes and rule configuration ...
Page 80: ...80 W T WireGuard VPN client ...
Page 84: ...84 W T WireGuard VPN Box to Box ...
Page 111: ...111 W T Subject to error and alteration Appendix Technical data and form factor ...