TMS zl Module Planning and Implementation Guide 2009-08

Table Of Contents
Page 21
Figure 6: Data Center Compartmentalization Security Control Point
A security enclave is an even higher security area within the enterprise network. The
conversion of the data center into an enclave is simply one of the more obvious
applications of this concept. In the above figure, the data center has been made into an
enclave with compartments within the enclave. In Figure 7, the entire data center has
been converted into an enclave without compartmentalization within the resulting
enclave:
Figure 7: Data Center Enclave Security Control Point
The HP ProCurve Threat Management Services zl Module can:
Use the firewall feature to compartmentalize different types of servers and the
services they offer using different security zones within the data center and/or limit
traffic coming in to the data center to only that required to use the services offered
by designated servers. For example, SNMP Traps going to the Management
Servers, SMB file sharing traffic headed to the File Servers, Active Directory /