Re: [fw-wiz] Flat vs Segmented DMZ's

From: Luca Berra (bluca@comedia.it)
Date: 11/21/02


From: Luca Berra <bluca@comedia.it>
To: firewall-wizards@honor.icsalabs.com
Date: Thu Nov 21 20:33:18 2002

On Wed, Nov 06, 2002 at 08:28:52AM -0800, WhtWlf2001 wrote:
>I'm hoping to get some feedback (Pros/Cons) from the list members on a Flat vs. Segmented DMZ
>structure. We currently have about 20 hosts segmented off to 4-5 different DMZ interfaces on a CP
>firewall. With the exception of having a seperate MGMT DMZ, I'm curious about the
>benefits/detriments to having this segmented infrastructure. Today we offer only limited web
>services (http,ftp,owa) via the web.

Anyone has had any experience on using the Cisco 650x firewall blade to
obtain this?

-- 
Luca Berra -- bluca@comedia.it
        Communication Media & Services S.r.l.
 /"\
 \ /     ASCII RIBBON CAMPAIGN
  X        AGAINST HTML MAIL
 / \