Re: [fw-wiz] Firewalls and 802.1q trunking

From: Carson Gaspar (carson@taltos.org)
Date: 11/27/02


From: Carson Gaspar <carson@taltos.org>
To: "'firewall-wizards@honor.icsalabs.com'" <firewall-wizards@honor.icsalabs.com>
Date: Wed Nov 27 00:04:02 2002

My personal philosophy is that VLAN trunks are OK within a risk zone, but
not between them. This is the usual risk / reward tradeoff. VLAN trunks
trade expensive or non-available firewall ports for cheap and plentiful
switch ports, with the risk being an attack on the switch. I'm willing to
make that tradeoff to some extent, but not to the point of having
everything connected to one switch, and relying entirely on the switch to
provide separation.

The sticky bit is, how do you divide your zones by risk? At a bare minimum,
I put Internet, DMZ, and internal segments on different physical switches.
If there are third party external non-Internet links, I'd like those to be
seperate as well. If I have firewall ports left, I like to break up the
DMZs into authenticated / non-authenticated, front-end / back-end, inbound
/ outbound, or by operational criteria such as maintenance widows (very
useful with virtual firewalls) - the specifics are usually site specific.

-- 
Carson


Relevant Pages

  • Re: Everyone got their generator ready?
    ... I have said it was not safe, that there was a risk to the linesman, but very much lower than you implied, and a greater risk to the family. ... I also agreed that the safest and proper method was to use a changeover switch and permanent wiring. ... Please remember this discussion is about the risk to a linesman because folk might have connected a generator to their house wiring without isolating it from the grid. ... Dick or Harry's electrician has ...
    (uk.business.agriculture)
  • Re: Everyone got their generator ready?
    ... This is just one incident to illustrate a point. ... are away and the wife gets the neighbour to switch the thing on. ... The risk *is* ...
    (uk.business.agriculture)
  • Re: VLANS in a DMZ - good idea?
    ... in the best of all worlds you should place each security zone on a physical ... >placing multiple vlans on the same switch including different zones is IMHO an acceptable ... >low probability risk that a switch might be compromised I feel it is better to not introduce ... As I rock, rock, rock, rock, rock the microphone ...
    (comp.security.firewalls)
  • Re: Logging in
    ... You can not log out if you're happy with the risk that someone else will ... For many home computers, including ... More annoying are Nokia mobile phones that, when you switch them off, ...
    (alt.usage.english)
  • Re: [PATCH] x86_64: resize NR_IRQS for large machines (re-submit)
    ... enough to make it worth the risk, ... so it has to be something worth fighting for. ... the switch is toggled, nr_irqs is a variable, otherwise it's a carbon ... x86 and most drivers can be converted to nr_irqs. ...
    (Linux-Kernel)