Enforcing network security: a real cease study in a research organization

For a research organization access to the Internet is a primary need and researchers like to use remote resources in the most natural way: as if everything were local. Unfortunately such a wish is very often in conflict with another need: the protection of computing and networking assets from external threats. In this paper we report about the activities carried on in our Institute to improve the security of the local network. A number of tradeoffs between complexity, cost and security level are described along with the particular choices we have made.