Re: Firewall design [was: Re: Best security topology for FreeBSD]
From: Giorgos Keramidas (charon@labs.gr)
Date: 11/23/01
- Next message: Cy Schubert - ITSD Open Systems Group: "Re: Best security topology for FreeBSD"
- Previous message: veedee@c7.campus.utcluj.ro: "Re: natd: failed to write packet back (Permission denied)"
- In reply to: Krzysztof Zaraska: "Firewall design [was: Re: Best security topology for FreeBSD]"
- Next in thread: Crist J. Clark: "Re: Firewall design [was: Re: Best security topology for FreeBSD]"
- Messages sorted by: [ date ] [ thread ] [ subject ] [ author ] [ attachment ]
Date: Fri, 23 Nov 2001 12:28:09 +0200 From: Giorgos Keramidas <charon@labs.gr> To: Krzysztof Zaraska <kzaraska@student.uci.agh.edu.pl>
[ ascii art reordering to cut a few lines of text ]
Internet --- firewall --- internal
|
DMZ
------------------------------------------------------------
Internet --- firewall1 --- DMZ --- firewall2 --- internal
------------------------------------------------------------
On 2001-11-22 20:55:30, Krzysztof Zaraska wrote:
> Could you please explain why the second design is better? I know it's
> harder to properly construct the correct ruleset for the first topology,
> but what are other problems?
Two levels of firewall; one more barrier for intruders. If the same
machine is used for the DMZ and internal firewall, and it is
compromised, then both the DMZ and internal networks are wide open.
This however is useless if you use exactly the same hardware/software
both for the `external' and `internal' machines and still have two
separate machines for the two firewalls. The same exploits/bugs that
will let someone in at the external firewall, will let him break the
internal firewall when the DMZ has been compromised.
But by now we are deep into the paranoia territory :)
-giorgos
To Unsubscribe: send mail to majordomo@FreeBSD.org
with "unsubscribe freebsd-security" in the body of the message
- Next message: Cy Schubert - ITSD Open Systems Group: "Re: Best security topology for FreeBSD"
- Previous message: veedee@c7.campus.utcluj.ro: "Re: natd: failed to write packet back (Permission denied)"
- In reply to: Krzysztof Zaraska: "Firewall design [was: Re: Best security topology for FreeBSD]"
- Next in thread: Crist J. Clark: "Re: Firewall design [was: Re: Best security topology for FreeBSD]"
- Messages sorted by: [ date ] [ thread ] [ subject ] [ author ] [ attachment ]
Relevant Pages
|