Re: [fw-wiz] Internet accessible screened subnet - use public orprivate IPs?

From: David Lang (david.lang_at_digitalinsight.com)
Date: 07/22/05

  • Next message: David Lang: "Re: [fw-wiz] Intel vs. special purpose FW-1 servers"
    To: "Paul D. Robertson" <paul@compuwar.net>
    Date: Thu, 21 Jul 2005 18:28:22 -0700 (PDT)
    
    

    On Thu, 21 Jul 2005, Paul D. Robertson wrote:

    > On Fri, 15 Jul 2005, Matt Bazan wrote:
    >
    >> Is there a preferred method of setting up a Internet facing screened
    >> subnet and the use of public or private IP addresses? Looking at
    >> redesinging our DMZ to only include public resources (www, smtp, imap,
    >> ftp). Presently we use a private IP address range for this that is
    >> NAT'ed at our firewall. Any reasons to change this policy to using
    >> public IPs in the DMZ? Thanks,
    >
    > If you're NATing to your internal network, then a rework is necessary-
    > public stuff should be on its own (preferably) physical subnet.
    >
    > IP addressing doesn't matter much, since you'll be letting stuff through
    > the most likely exploit vectors anyway.

    The thing I've been eharing for years about why NAT is better is that you
    may change ISP's and end up with a new set of IP addresses which are
    easier to change if you NAT.

    this may be true (I've actually never seen anyone acutally DO this), but
    you are trading one-time headaches (which I personally believe are no more
    severe then all the other changes that you need to make when changing
    things, firewalls, DNS, NAT tables, etc) for ongoing overhead (performance
    on your NAT device, troubleshooting, bugs in the NAT implementation,
    overloading of the NAT tables, etc)

    I would definantly have things that server the Internet use public
    addresses, once you get behind that layer and have devices that only talk
    to internal stuff, then make it all private addresses.

    David Lang

    -- 
    There are two ways of constructing a software design. One way is to make it so simple that there are obviously no deficiencies. And the other way is to make it so complicated that there are no obvious deficiencies.
      -- C.A.R. Hoare
    _______________________________________________
    firewall-wizards mailing list
    firewall-wizards@honor.icsalabs.com
    http://honor.icsalabs.com/mailman/listinfo/firewall-wizards
    

  • Next message: David Lang: "Re: [fw-wiz] Intel vs. special purpose FW-1 servers"

    Relevant Pages

    • Re: Using a Linksys router, should I also use Zonealarm? Internet Acceptable Use Policy
      ... my browser's access to the Internet is restricted. ... I thought it was the company's firewall extending a slap on my ... > public internet to access corporate network. ... > NAT is Network Address Translation. ...
      (microsoft.public.security)
    • Re: Whats the difference between NAT and a FIREWALL?
      ... NAT is network address translation: basically a router that routes between ... company/home users) get on the internet with just one public IP address from ... A firewall is any router that has rules on it that filter ... A proxy server is a server that acts as a router, but at a higher level on ...
      (comp.security.firewalls)
    • Re: NAT router
      ... interface to subnet 255.255.255.0 and the subnet of the external interface to ... The RRAS NAT box will *replace* any other "NAT router" that may be there. ... If your network already connects to the Internet through a NAT router you do not need NAT on your server. ...
      (microsoft.public.windows.server.networking)
    • Re: Please Help me to block the hackers
      ... It's typical to use a firewall and NAT with private IP address ranges. ... NAT device in order to reach the internet. ...
      (microsoft.public.security)
    • Re: any suggestion for a good hardware firewall
      ... have had 4 or 5 computers on the public internet for quite some time.. ... I'm not clear on how to configurea firewall for this network situation. ... has a need for 5 IP or he would have already used a simple NAT device to ... want a cheap firewall appliance ...
      (comp.security.firewalls)