[fw-wiz] firewall in the management subnet

From: Roger Barbeau (r_barbeau_at_videotron.ca)
Date: 09/19/03

  • Next message: Mike Hoskins: "Re: [fw-wiz] how to check if someone is blocking me or watching me?"
    To: firewall-wizards@honor.icsalabs.com
    Date: Fri, 19 Sep 2003 14:44:23 -0400


    I would like to know your opinion about a firewall configuration issue:

    We plan to configure our firewall management module (checkpoint firewall NG)
    on a server that shares its network connection (subnet) with other servers
    used for management purposes (SNMP, BACKUPS, .) in order to save one
    firewall network interface.


    Internet ---- FW ------ subnet 1 Server that hosts the FW Management Module
                         L----- subnet 1 Management server 1 (SNMP)
                       L----- subnet 1 Management server 2 (BACKUPS)

    I understand that having a separate network interface for the firewall
    management module is a better practice.

    Nevertheless, this configuration is cost effective and has an impact on the
    number of available network interfaces for other needs.

    What are your recommendations?

    Best regards,


    firewall-wizards mailing list

  • Next message: Mike Hoskins: "Re: [fw-wiz] how to check if someone is blocking me or watching me?"

    Relevant Pages

    • Re: Security SBS2003 and Broadband
      ... the best scenario is a router attached to a 2nd network interface on the ... > I have a server with SBS2003 and Cable broadband. ... > should I go for a Router/hardware firewall or is the SBS firewall ... > I don't like the idea of a router as it gives the internet to every other ...
    • Re: How to discover FW-1 management module or GUI?
      ... >> How can i discover in a LAN the management module or the PC that run FW-1 ... with the firewall module, in the very familiar checkpoint format i.e. ... This list is provided by the SecurityFocus Security Intelligence Alert ...
    • Check Point FW1 NG FP3 Management Module
      ... I have a Check Point Firewall with the enforcement module and the ... Management module installed on the same machine. ... Both componenets were installed as a distributed install on windows ...
    • Re: CEICW fails at firewall config
      ... Do you or do you not have ISA 2000 or ISA 2004 installed on the SBS server? ... Do you have 2 NICs in the SBS? ... CEICW fails on firewall configuration every time. ... >>> Call to Creating the protected networks access rule returned ok. ...
    • Re: Recycler security issues on IIS server
      ... > latest upates to the server. ... > like to see the server put behind our firewall, ... other software, install all patches, IISlockdown, URLscan, use the correct ... the procedures you follow may vary depending on your security needs. ...