[fw-wiz] Internet accessible screened subnet - use public or private IPs?

From: Matt Bazan (Mbazan_at_onelegal.com)
Date: 07/15/05

  • Next message: Darren Reed: "Re: [fw-wiz] Is NAT in OpenBSD PF UPnP enabled or Non UPnP?"
    To: <firewall-wizards@honor.icsalabs.com>
    Date: Fri, 15 Jul 2005 13:01:45 -0700
    
    

    Is there a preferred method of setting up a Internet facing screened
    subnet and the use of public or private IP addresses? Looking at
    redesinging our DMZ to only include public resources (www, smtp, imap,
    ftp). Presently we use a private IP address range for this that is
    NAT'ed at our firewall. Any reasons to change this policy to using
    public IPs in the DMZ? Thanks,

      Matt

    _______________________________________________
    firewall-wizards mailing list
    firewall-wizards@honor.icsalabs.com
    http://honor.icsalabs.com/mailman/listinfo/firewall-wizards


  • Next message: Darren Reed: "Re: [fw-wiz] Is NAT in OpenBSD PF UPnP enabled or Non UPnP?"

    Relevant Pages

    • Re: W2K3 domain in DMZ
      ... > Yes a single domain DMZ ... > Private subnet on 2nd NIC ... > server, ...
      (microsoft.public.windows.server.security)
    • Re: About Firewall configuration
      ... The Server machine is not DMZ, so can it use Private IP only? ... The router machine is a general router machine which provided by ISP, ... Give a lot of thought to your network design and what you want to do with ...
      (Fedora)
    • Re: Network Security Design
      ... > connected to DMZ and the other connected directly to the Private ... the services and hosts you put in the DMZ are the ones that get ... > that are needed by internal users and public users. ... but if the DMZ is also a private network and depends on portforwarding, ...
      (comp.security.firewalls)
    • Re: [fw-wiz] Internet accessible screened subnet - use public or private IPs?
      ... Presently we use a private IP address range for this that is ... > public IPs in the DMZ? ... public stuff should be on its own physical subnet. ... Paul D. Robertson "My statements in this message are personal opinions ...
      (Firewall-Wizards)
    • Re: Help with security design documentation
      ... If you believe that having a three networks (DMZ, public, private) reduces your security risk, then it's obviously silly to say "we have a private network that we run a public server on, and a DMZ with nothing on it, and a public network to talk to the empty DMZ". ...
      (microsoft.public.security)