[fw-wiz] Maximum number of subnets on a firewall

From: Paolo Supino (paolo_at_telmap.com)
Date: 02/12/04

  • Next message: Jeremiah Cornelius: "Re: [fw-wiz] Vlan's as effective security measures?"
    To: firewall-wizards@honor.icsalabs.com
    Date: Thu, 12 Feb 2004 21:33:47 +0200
    
    

    Hi

      A couple of weeks ago I sent an email about a possible firewall layout for
    3 companies. After reading the answers and doing some drawings in visio (if
    anyone has has a better tool, please le me know) I setup the firewall in the
    following way
    (BTW: Their needs turned out to be more complex than simply having a LAN
    segment a DMZ segment and an outside segment for each of them):
    1. a Single firewall for all 3 companies. This is because all 3 companies
    will also share the same outsourced IT department.
    2. Each company gets a segment to for their company LAN.
    3. There is 1 segment that is considered internet segment where all
    companies will have their internet servers.
    4. Each of the companies needs/wants a segment where they can setup their
    own product's servers and want to be able to control the source IP of the
    client closely on a need basis and don't want to share the same segment.
    5. 1 segment is connected to the router.
    6. The company giving the IT service insisted on having all resources in 1
    room and have separate segment for out of band management of the servers.
    7. 1 segment will have a WIFI access point connected to it and according to
    the logon user used access will be granted to the right lans (tried to
    object to this but failed).

      This setup was made resdundent by having an active-passive duo setup.
    That's it, comments, ideas are welcome.

            Paolo
    _______________________________________________
    firewall-wizards mailing list
    firewall-wizards@honor.icsalabs.com
    http://honor.icsalabs.com/mailman/listinfo/firewall-wizards


  • Next message: Jeremiah Cornelius: "Re: [fw-wiz] Vlan's as effective security measures?"

    Relevant Pages

    • Re: 3 NICs on Windows 2k3
      ... >I currently use Win2k3 as a router providing shared access to an Internet ... > connection from my LAN. ... > (as obviously we are all inside the firewall). ... > another NIC to my server which can be used as a seperate segment for the ...
      (microsoft.public.win2000.ras_routing)
    • [fw-wiz] RE: firewall-wizards digest, Vol 1 #679 - 2 msgs
      ... This is using a single DMZ (simple firewall) for the servers ... to host VPN engine. ... |> What we want to do is control which servers on the segment talk among ...
      (Firewall-Wizards)
    • Re: [fw-wiz] segmentation of DMZs
      ... Every system is on a seperate segment ... Address space nightmare (can be solved with a bridging firewall) ... High operational / debugging complexity ... complex routing, virtual firewalls, bridging, and 802.1q. ...
      (Firewall-Wizards)
    • Re: [fw-wiz] Maximum number of subnets on a firewall
      ... about the security policy for each segment and how it relates to each ... Company A doesn't talk to Company B, the DMZs don't have any traffic ... The management network, depending on how much stuff its connected to, ... traverse the firewall to get where it's going. ...
      (Firewall-Wizards)
    • Re: How expand domain subnet?
      ... But if my LAN was going to contain less than 200 Ethernet nodes, ... subnet would reduce the number of possible clients to 62. ... Add a new segment. ... and VPN clients (managed by PIX firewall). ...
      (microsoft.public.windows.server.networking)