Design Reference

Table Of Contents
not only static TCP and UDP ports, like Telnet or HTTP, but also applications that create and use
dynamic ports, such as FTP, and audio and video streaming. For every packet, the state-aware
firewall finds a matching flow and conversation.
The following figure shows a typical configuration used in firewall load balancing.
Figure 79: Firewall load balancing configuration
Use this configuration to redirect incoming and outgoing traffic to a group of firewalls and to
automatically load balance across multiple firewalls. The benefits of such a configuration are:
Increased firewall performance
Reduced response time
Redundant firewalls ensure Internet access
Virtual private networks (VPN) replace the physical connection between the remote client and
access server with an encrypted tunnel over a public network. VPN technology employs IP security
(IPsec) and the Secure Sockets Layer (SSL) services.
Several Avaya products support IPsec and SSL, including Avaya VPN Gateway and Secure Router.
Additional information
The following organizations provide the most up-to-date information about network security attacks
and recommendations about good practices:
The Center of Internet Security Expertise (CERT)
The Research and Education Organization for Network Administrators and Security
Professionals (SANS)
The Computer Security Institute (CSI)
System and network stability and security
160 Network Design Reference for Avaya VSP 4000 Series June 2015
Comments on this document? infodev@avaya.com