Re: [fw-wiz] Defense in Depth to the Desktop
From: Magosányi Árpád (mag_at_bunuel.tii.matav.hu)
Date: 12/06/04
- Previous message: Christopher Hicks: "Re: [fw-wiz] Forward 2 networks"
- In reply to: Chris Pugrud: "[fw-wiz] Defense in Depth to the Desktop"
- Next in thread: Chris Pugrud: "Re: [fw-wiz] Defense in Depth to the Desktop"
- Reply: Chris Pugrud: "Re: [fw-wiz] Defense in Depth to the Desktop"
- Messages sorted by: [ date ] [ thread ] [ subject ] [ author ] [ attachment ]
To: Chris Pugrud <cpugrud@yahoo.com>, firewall-wizards@honor.icsalabs.com Date: Mon, 6 Dec 2004 08:40:42 +0000
A levelezőm azt hiszi, hogy Chris Pugrud a következőeket írta:
> Overview
>
[one subnet for servers, one for clients, separated by a firewall]
> In addition to the firewall, the client systems are fully isolated from each
> other by layer 2 controls (private vlans). The servers may be similarly
> isolated, but doing so is minimally effective and damaging to server to server
> communications.
It is interesting to note that what you propose can be viewed as an
example of the Bell-LaPadula modell with two security levels.
There are questions regarding the scaleability and the resource needs of
such a setup.
-How can you scale it to an intranet which have hundreds or thousands of
subnets, with tens or hundreds of separate application servers
geographically scattered?
My answer would be using VPNs, which makes configuration and network
usage more resource intensive.
-What approaches could you use to minimize configuration overhead and
network resource utilisation, especially on a large intranet?
You also seem to forget that there is a world beyond Microsoft, but
this have little impact on the question.
-- GNU GPL: csak tiszta forrásból _______________________________________________ firewall-wizards mailing list firewall-wizards@honor.icsalabs.com http://honor.icsalabs.com/mailman/listinfo/firewall-wizards
- Previous message: Christopher Hicks: "Re: [fw-wiz] Forward 2 networks"
- In reply to: Chris Pugrud: "[fw-wiz] Defense in Depth to the Desktop"
- Next in thread: Chris Pugrud: "Re: [fw-wiz] Defense in Depth to the Desktop"
- Reply: Chris Pugrud: "Re: [fw-wiz] Defense in Depth to the Desktop"
- Messages sorted by: [ date ] [ thread ] [ subject ] [ author ] [ attachment ]
Relevant Pages
|
|