MAP Internal and DMZ Servers

From: Tony Lindsey (tonylindseyt@excite.com)
Date: 03/26/03

  • Next message: Tim Heagarty: "Managing Multiple OpenBSD-IP Filter firewalls"
    To: security-basics@securityfocus.com
    From: "Tony Lindsey" <tonylindseyt@excite.com>
    Date: Wed, 26 Mar 2003 13:24:32 -0500 (EST)
    

    Hi,

    Our server group wants to MAP some production servers from inside our network to servers out on our DMZ. The reason they want to do this is to easily load software upgrades and patches between the internal and DMZ servers. Another reason is to easily inspect the logs on some of the high traffic DMZ servers from servers within our network. At this point I am not sure what services/ports on the internal DMZ firewall should be open.

    What are the security risks? I know there have been some vulnerabilities associated with NFS. Should I deny the security request?

    Tony Lindsey
    Audit Security and Risk Management Group
    Managed Medical Services LLP
    U.S. Division

    _______________________________________________
    Join Excite! - http://www.excite.com
    The most personalized portal on the Web!

    -------------------------------------------------------------------
    SurfControl E-mail Filter puts the brakes on spam,
    viruses and malicious code. Safeguard your business
    critical communications. Download a free 30-day trial:
    http://www.surfcontrol.com/go/zsfsbl1


  • Next message: Tim Heagarty: "Managing Multiple OpenBSD-IP Filter firewalls"

    Relevant Pages

    • REVIEW: "Enterprise Security", David Leon Clark
      ... %T "Enterprise Security: The Manager's Defense Guide" ... is e-business," and, with a little re-interpretation of history (the ... Countermeasures and attack ... Part four deals with active defense mechanisms and risk management. ...
      (comp.security.misc)
    • Re: Software Registry: is "Advanced INF" legit Explorer?
      ... (can you completely trust a backup made from an infected machine? ... Security is about risk management - ergo, ... can't say that you'll avoid infecting your newly flattened and rebuilt ...
      (comp.security.misc)
    • Re: Canned audits
      ... "Perform an objective assessment of your security and risk management profile using a simple interview process ... Generate a Risk Assessment Value that quantifies your risk management using a standardized, ...
      (Pen-Test)
    • RE: Security configuration steps for multiple site hosting
      ... I'm concerned about the security risks involved with ... any chances of security breaches or performance ... Is there an "IIS Security for Dummies" book available? ... In order to isolate webapplications, ...
      (microsoft.public.inetserver.iis.security)
    • Re: TS on a domain controller
      ... What do you all think about the benefits of user management from ... security risks inherent to AD and TS being on the same box? ... running on a domain controller poses security risks. ...
      (microsoft.public.windows.terminal_services)