DMZ Design and Functionality

From: Dana Rawson (absolutezero273c_at_nzoomail.com)
Date: 08/18/03

  • Next message: Arturo \: "Re: Best IP configuration for OpenBSD firewall/router"
    Date: 18 Aug 2003 19:52:40 -0000
    To: security-basics@securityfocus.com
    
    
    ('binary' encoding is not supported, stored as-is)

    Forgive me if these questions are too basic but I am relatively new to
    this. I am the network administrator at my company and over the past year
    have become aware of a need for increased security. I have been reading
    posts here in hopes of learning more about this. While I have learned
    considerable amounts, and have searched for answers elsewhere, I am still
    in need of guidance. Any help or direction would be greatly appreciated.
    I am open to reading any books that one might recommend. I have seen a
    few books out there but not sure which are worthwhile.

    Anyway, my background information is this:
    I wanted to install a DMZ at 2 of my company's locations. I do have a
    limited budget so I was planning on using OpenBSD for my first tier
    firewall. I do have a hardware based firewall in place currently which I
    was planning on using as my second tier firewall.
    My initial plan is to build a machine using OpenBSD that does nothing but
    firewall. Additionally, I wanted to add another machine to run
    Sendmail/SpamAssassin and an an anti-virus software. On this I was hoping
    to run Redhat as this is what I am most knowledgeable on. My thought
    behind this was to block spam, of course, and also run a gateway anti-
    virus solution that would block viruses coming from websites and
    employee's personal e-mail accounts. This due to the fact that I have
    seen a number of viruses coming in from either their 'webmail' or through
    their Outlook Express. I wish to set up an ftp server and webserver to
    facilitate OWA. Additionally I would like to make available VPNs and
    encrypt all data transmitted over remote connections. Remote connections
    may consist of a MS RAS and Citrix.

    With this information my questions are:

    1. To begin, does this sound like an acceptable solution?
    2. How do I size the machine that I am going to run OpenBSD? I have read
    that a DMZ will slow performance down some. If I have a fast enough
    machine will it aid performance? At what point is overkill when running
    OpenBSD.
    3. How do I size the machine that will be running Redhat, Sendmail and
    SpamAssassin? Is this configuration acceptable? Should the Anti-virus
    software be running on a separate machine?
    4. What open source options to I have for encryption and VPNs?
    5. Are there any potential problems running this configuration? Does
    everything mentioned here play nice together? Would you change anything
    here and if so why?

    Many thanks in advance.

    Dana

    ---------------------------------------------------------------------------
    ----------------------------------------------------------------------------


  • Next message: Arturo \: "Re: Best IP configuration for OpenBSD firewall/router"

    Relevant Pages

    • Re: The Stunning Failure of OpenBSD
      ... To make the long story short, request your boss to spend about US$100 from ... his petty account to get any router + Firewall + NAT + QoS, ... to replace your Linux router. ... OpenBSD proved to be more ...
      (comp.os.linux.security)
    • Re: Internet Sharing - Security
      ... Can you recommend the steps that I would need to take once I have ... OpenBSD 3.0 installed on my system. ... >>>inexpensive Linux 2.4.x firewall with Netfilter and ISC DHCP is fine. ...
      (comp.security.firewalls)
    • Re: What firewall for small medical research lab
      ... There is no BEST firewall, if you will not use it at the right ... Then I found OpenBSD and stayed with it since. ... As far as cost, $45 for OpenBSD ... Try Webroot's Spy Sweeper Enterprisefor 30 days for FREE with no ...
      (Security-Basics)
    • Re: Which Linux OS best for beginner to setup as Web / Mail server / Internet sharer and firewall?
      ... >>I don't want to start a flame war, but in my experience OpenBSD is best ... >>boxes if you must run linux for applications. ... > linux inside the firewall? ... web server? ...
      (comp.os.linux.networking)
    • Re: RX (download) limit problem
      ... > I've been seeing a strange problem with my 5.4-STABLE freebsd ... > behind it or the firewall itself) can get a decent rate. ... > In talking to some openBSD guys we had a theory that it might be something ... > the upload and download being kept symmetric and hence so low on the ...
      (freebsd-current)

  • Quantcast