RE: [fw-wiz] monitoring and controlling servers on internet segme nt

Richard.Bertolett_at_ci.austin.tx.us
Date: 05/04/04

  • Next message: Shimon Silberschlag: "Re: [fw-wiz] monitoring and controlling servers on internet segment"
    To: shimons@bll.co.il
    Date: Tue, 4 May 2004 08:34:34 -0500
    
    

    Shimon,
    If your firewall will support another NIC, then I would say that the below
    case is a prime candidate for a DMZ setup. You could then put the
    'Intermediary server' there, and use it to update the intranet. Further to
    that, you could also consider moving other servers there as well, for
    instance the web server (if there is one.) You then use a simple forward
    caching server out on the internet. The goal here is to provide as small an
    attack profile as possible to the internet.

    Regards,
    Rick Bertolett
    Austin Water Utility
    512-972-0225

    -----Original Message-----
    From: Shimon Silberschlag [mailto:shimons@bll.co.il]
    Sent: Tuesday, May 04, 2004 4:53 AM
    To: firewall-wizards@honor.icsalabs.com
    Subject: [fw-wiz] monitoring and controlling servers on internet segment

    Lets say that a client have various servers on an internet segment, which is
    separated from the internal network with a firewall.
    The client wants to have an agent reporting various events back to the
    management center, which is on the internal net. The protocol in use uses
    fixed ports, and is encrypted with mutual authentication between machines.
    The client does not want to open up all servers to the internal net, so he
    puts an intermediary server on the internet segment, which gets the reports
    from all internet servers, and pushes them to the management center on the
    inside. There is no option to poll the intermediary.
    The only other option is to install a separate management center for the
    internet segment, with the associated costs in purchase and maintenance.

    Would using such a setup (the intermediary one) constitute good, bad or best
    practice?

    Shimon Silberschlag

    +972-3-9351572
    +972-51-207130

    _______________________________________________
    firewall-wizards mailing list
    firewall-wizards@honor.icsalabs.com
    http://honor.icsalabs.com/mailman/listinfo/firewall-wizards
    _______________________________________________
    firewall-wizards mailing list
    firewall-wizards@honor.icsalabs.com
    http://honor.icsalabs.com/mailman/listinfo/firewall-wizards


  • Next message: Shimon Silberschlag: "Re: [fw-wiz] monitoring and controlling servers on internet segment"

    Relevant Pages

    • Re: login attempts
      ... > Every day i have on my win2000 iternet server a lots of wrong login ... Windows by default allows ... You also need a firewall. ... the internet, except for those ports you know you're using. ...
      (microsoft.public.win2000.security)
    • Re: Firewall on a single NIC SBS2003 Standard edition
      ... Frank McCallister SBS MVP ... > " Well, if you're wanting to run the firewall on a single NIC, you aren't ... Don't ask the server to do *everything*, ... > internet traffic from the workstations don't have to go through the SBS. ...
      (microsoft.public.windows.server.sbs)
    • Re: Internet on nodes
      ... I stopped the Firewall in SBS and could upload ... print' from both the server and a WS. ... Was not able to connect to the internet on the WS. ...
      (microsoft.public.windows.server.sbs)
    • Re: 2 NICs Configuration Problem
      ... the server as Paul envisaged it. ... gateway (to the Internet through the NIC connected to the Sonicwall DMZ ... NICs should not have default gateways configured for both. ... DMZ ports of any firewall, is an alternative path that cause great ...
      (microsoft.public.windows.server.networking)
    • Re: XP/SP2 Firewall über W2K GPO deaktivieren
      ... Weil es einen zentralen Zugangpunkt zum Internet gibt und dieser geschützt ... Dafür sorgt der Proxy Server für die Mitarbeiter. ... Meine Clients haben auch keine lokale Firewall installiert, ...
      (microsoft.public.de.german.win2000.gruppen_richtlinien)

    Loading