The first line in defending CERN against malicious traffic from the Internet is CERN's outer perimeter firewall. Following a well-defined set of rules, this firewall permits or denies any incoming network traffic to communicate with CERN hosts and controls outgoing traffic towards the Internet. System administrators can usually request firewall openings for the servers they are responsible for by using the LANDB Web interface (http://network.cern.ch). These requests are approved or rejected following the result of a subsequent security scan performed by the Computer Security Team.
>>