Re: Firewall and DMZ topology
From: Chris Berry (compjma_at_hotmail.com)
Date: 06/10/03
- Previous message: Mann, Bobby: "RE: Firewall and DMZ topology"
- Maybe in reply to: William J. Burgos: "Firewall and DMZ topology"
- Next in thread: David Gillett: "RE: Firewall and DMZ topology"
- Reply: David Gillett: "RE: Firewall and DMZ topology"
- Reply: Erik Vincent: "Re: Firewall and DMZ topology"
- Reply: Daniel B. Cid: "Re: Firewall and DMZ topology"
- Reply: Des Ward: "RE: Firewall and DMZ topology"
- Reply: Christopher Ingram: "Re: Firewall and DMZ topology"
- Messages sorted by: [ date ] [ thread ] [ subject ] [ author ] [ attachment ]
To: security-basics@securityfocus.com Date: Mon, 09 Jun 2003 17:53:07 -0700
>From: Christopher Ingram <cmi@crystalsands.net>
>So, the below setup is not decent for a corporate LAN. Ideally, the DMZ
>should sit on a seperate connection to the Internet from the rest of the
>network, using a different ISP and therefore, different IP block. This
>provides the most isolation.
I'm afraid I don't see how that:
internet --> Firewall --> Lan
internet --> Firewall --> DMZ
would be any more secure than this:
internet --> Outer Firewall --> DMZ --> Inner Firewall --> LAN
or this:
internet --> Firewall --> LAN
--> DMZ
which are the setups that I've seen. Can you give some
justification/explanation on why you think that would be better?
Chris Berry
compjma@hotmail.com
Systems Administrator
JM Associates
"All I want is a few minutes alone with the source code for the universe and
a quick recompile."
_________________________________________________________________
STOP MORE SPAM with the new MSN 8 and get 2 months FREE*
http://join.msn.com/?page=features/junkmail
---------------------------------------------------------------------------
Evaluating SSL VPNs' Consider NEOTERIS, chosen as leader by top analysts!
The Gartner Group just put Neoteris in the top of its Magic Quadrant,
while InStat has confirmed Neoteris as the leader in marketshare.
Find out why, and see how you can get plug-n-play secure remote access in
about an hour, with no client, server changes, or ongoing maintenance.
Visit us at: http://www.neoteris.com/promos/sf-6-9.htm
----------------------------------------------------------------------------
- Previous message: Mann, Bobby: "RE: Firewall and DMZ topology"
- Maybe in reply to: William J. Burgos: "Firewall and DMZ topology"
- Next in thread: David Gillett: "RE: Firewall and DMZ topology"
- Reply: David Gillett: "RE: Firewall and DMZ topology"
- Reply: Erik Vincent: "Re: Firewall and DMZ topology"
- Reply: Daniel B. Cid: "Re: Firewall and DMZ topology"
- Reply: Des Ward: "RE: Firewall and DMZ topology"
- Reply: Christopher Ingram: "Re: Firewall and DMZ topology"
- Messages sorted by: [ date ] [ thread ] [ subject ] [ author ] [ attachment ]
Relevant Pages
|