Best Practices - DMZ Security.

From: tony toni (tony572001@hotmail.com)
Date: 10/30/02


From: "tony toni" <tony572001@hotmail.com>
Date: Wed, 30 Oct 2002 12:09:53 -0800


Hi,

What are the best security practices for a DMZ? Or put a different
way...what are things you should never allow to be done on a DMZ? To give
you an example of what I am talking about we have had our DMZ set up for
about 5 years. However we keep getting stranger requests for activities
that want to be done on the DMZ. Examples include: setting up a chat server
on the DMZ, opening up our firewall so various groups can use "Polycom web
cams" for video conferencing, vendors that want to ssh directly into are
internal servers, backing up DMZ servers to internal servers, etc.

I am working with our firewall administrators and trying to establish
guideline/standards. What would you recommend in the areas of:
  .general DMZ security design considerations?
  .services to allow?
  .ports that should be open/closed?
  .vendor/employee use of DMZ?

Is there a white paper somewhere that addresses these and other DMZ security
issues? I feel like our DMZ is designed appropriately...however it's
security is being eroded with all of the changes people want done to the DMZ
firewalls (use 4 of them...2 face internet and 2 face internal network)

Tony
IT Security Task Force Manager

_________________________________________________________________
Choose an Internet access plan right for you -- try MSN!
http://resourcecenter.msn.com/access/plans/default.asp



Relevant Pages

  • Re: DMZ NT4 TO Internal 2000 AD One-Way Trust via Firewall
    ... leverage an effectivity security policy to ensure that password complexities ... > currently a mess of local and domain users, no security policy, etc. ... DMZ, not publicly accessible) that aren't going away within the stated ... to non-DC web servers in the DMZ on 80 and 443 - none of which are directed ...
    (microsoft.public.windows.server.active_directory)
  • Re: webdav on SBS2003
    ... Traditional FW architecture describes a DMZ, ... DMZ and LAN. ... DMZ is that the entire server isn't exposed in the zone, ... you depend on Windows Security to ...
    (microsoft.public.windows.server.sbs)
  • Re: DMZ & Security
    ... > yes, deployement price, security level (depending what ... > open ports... ... > case what sense has my DMZ? ... if I have a web server on DMZ that have to access sqlserver database ...
    (microsoft.public.security)
  • RE: AD in the DMZ . . . OK?
    ... additional methods (i.e. IPSec, SSL with client authentication ... the DMZ and don't have a secure VPN tunnel that supports Kerberos, ... tunnel and/or a properly designed .NET app can minimize the risk. ... And security risk is always just a cost/benefit trade ...
    (Security-Basics)
  • Re: need advice on security scenarios
    ... You can get a Watchguard or Sonicwall firewall with a dedicated DMZ ... The best security scenario for placing the concentrator in relation to the ... > exception of the VPN concentrator, we don't run any other servers(web ...
    (microsoft.public.win2000.security)