RE: Secure Network Design (DMZ, LAN, etc)

From: Jef Feltman (feltman@pacbell.net)
Date: 08/22/02


Date: Thu, 22 Aug 2002 14:05:38 -0700
From: Jef Feltman <feltman@pacbell.net>
To: security-basics@securityfocus.com

there should be no problems with a switch and VLAN. A better choice would be
the 2 nics in each server and a private network behind the servers with the
database connected.

there are a couple of solutions for getting access to the database. the
easiest is to add another NIC and connect it to your inside network. do not
give the database a default gateway, that will prevent any packets from
getting outside your private network, only allowing access to servers and
where ever else you plugged it to.

jef

-----Original Message-----
From: booth monkey [mailto:boothmonkey@hotmail.com]
Sent: Tuesday, August 20, 2002 9:21 AM
To: tshoemaker@deltadentaltn.com; danielrm26@hotmail.com;
matthew@devney.net
Cc: security-basics@securityfocus.com
Subject: RE: Secure Network Design (DMZ, LAN, etc)

Perhaps there was some confusion from my diagrams...

I realize that this wasn't very clear but what I intended to illustrate was
that the web servers would in fact have 2 NICs each, one on the
192.168.1.0/24 network (for the load-balancer) and another one on the
10.10.10.0/24 (for talking to the databases). I've used this setup before
with no trouble (even through a shared switch with VLAN support).

Any thoughts on the IPTables vs. a commercial firewall thing?

BM.



Relevant Pages

  • Re: Win2K3 R2 x64 SP2 DNS & name resolution problem.
    ... You should not multihome your DC/DNS servers. ... Simply run the machines in one network with one NIC each. ... Set all machines on the virtual network to use the local DNS service and configure that local DNS to forward to the corporate DNS. ... Each of the 4 systems has 2 virtual NICs configured. ...
    (microsoft.public.windows.server.general)
  • Re: Domain Logon Speed
    ... Once in the new offices I certainly will be using a "formal" network ... NICs, DHCP and all the other things suggested in this ... you must specify that all servers and workstations specify ...
    (microsoft.public.windows.server.sbs)
  • Re: Problems Document sharing w/ 2000 server and crossover cable
    ... I did find the LMHOST file on both servers. ... I'm not a very good microsoft network guy. ... the NICs, and make sure there is no amber or red indications. ... output of CACLS of each server's shared folder (not the permissions on ...
    (microsoft.public.windows.server.networking)
  • Re: Multihoming Windows 2000
    ... > The thinking by some folks was to isolate the traffic by putting 2 NICS ... > other words the second switch and the 2 NICs on each host that makeup ... > this so called private network, ... You place the Servers on thier own dedicated Switch which would then ...
    (microsoft.public.win2000.networking)
  • Re: Viso and mapping SQL Servers
    ... A "network diagram" that shows the servers and how their related on the ... database - one diagram per database, or possibly per group of related ...
    (microsoft.public.sqlserver.server)