RE: DMZ Design

From: Daniel Miessler (danielrm26@hotmail.com)
Date: 07/18/02


From: "Daniel Miessler" <danielrm26@hotmail.com>
To: "'joe macdonald'" <joe_macdonald25@yahoo.com>, <security-basics@securityfocus.com>
Date: Thu, 18 Jul 2002 16:36:23 -0400

I recommend you check out this thread in the DSLR security forum:

http://www.dslreports.com/forum/remark,3811047~root=security,1~mode=flat
#3811047

If you have any questions after viewing that, let me know. In short
though, I suggest not using public IP's for your DMZ and/or Intranet.
If you are using Linux's 2.4 kernel and IPTABLES you can easily
implement NAT and have private address ranges for those networks. This
way, NAT stops all incoming requests from your DMZ to your internal
network just as it stops all incoming requests from the Internet to your
DMZ.

They key is having to specifically allow those connections in, which is
favorable to having them going by default. When you combine this with
solid packet filtering you are heading down the right path.

I strongly suggest Astaro for you also. The sheer number of features in
that product is mind boggling.

http://www.astaro.com

Again, let me know if you have any other questions. I will try to help
if I can.



Relevant Pages

  • Re: tpg cancel attack
    ... Internet connections to move traffic. ... common set of communications protocols. ... The vast collection of inter-connected networks across the world that ... A worldwide network of computer networks. ...
    (talk.politics.guns)
  • Re: Steve our posts have been deleted!!!!!
    ... That's due to the amount of bandwidth used for streaming! ... internet to serve 10-million listeners; there is simply no way the ... actually where in the coverage-zone of their terrestial networks. ... Of course, when you are talking about non-linear broadcasting, that's ...
    (alt.radio.digital)
  • RE: GPO that forces users to use a proxy server.
    ... as I would think home networks are not proxied and filtered. ... GPO that forces users to use a proxy server. ... proxy sever for there internet access in the company, ...
    (Focus-Microsoft)
  • Should Obama Control the Internet?
    ... Do you know about the Rockefeller Snowe job? ... A new bill would give the President emergency authority to halt web ... Should President Obama have the power to shut down domestic Internet ... concerning networks without regard to any provision of law, ...
    (alt.gathering.rainbow)
  • RE: How hackers cause damage...
    ... PBX and phone systems are PUBLIC networks. ... than list the internet as an agreed path. ... The cost of security is inverse ... Network Vulnerability Assessment project here in Australia and you may ...
    (Security-Basics)

Quantcast