Basic Network Configuration

From: Smith, KC (ksmith_at_systemsalliance.com)
Date: 10/14/03

  • Next message: Eric Maiwald: "Re: Securing iPAQ h3950 using Windows Mobile 2003"
    Date: Tue, 14 Oct 2003 12:40:12 -0400
    To: <security-basics@securityfocus.com>
    
    

    All,

    Okay I know this is truly a basic question, but this is after all the "security-BASICS" list!

    Most LAN configs I've seen include two, separate pieces of hardware to define the DMZ. A firewall on the outside and another firewall or policy switch on the inside is usually how I've seen that handled.

    My new company uses 3 separate NICs in the same firewall. One for inbound, one for the LAN and one for the DMZ. Each has it's own address block.

    It seems like using the firewall to do this makes sense, but I'd appreciate some external confirmation on that.

    The second issue is this: is there a rule of thumb to determine what should and should not go in the DMZ vs. the LAN? It seems to me that anything that requires access from outside the network (Ex. DNS servers, Mail servers, demo servers, etc.) should go in the DMZ. True?

    Thanks in advance.
    KC Smith

    ---------------------------------------------------------------------------
    ----------------------------------------------------------------------------


  • Next message: Eric Maiwald: "Re: Securing iPAQ h3950 using Windows Mobile 2003"

    Relevant Pages

    • Re: Basic Network Configuration
      ... A firewall on the outside and another firewall or policy ... >My new company uses 3 separate NICs in the same firewall. ... >one for the LAN and one for the DMZ. ...
      (Security-Basics)
    • Re: Basic Network Configuration
      ... A firewall on the outside and another firewall or ... > My new company uses 3 separate NICs in the same firewall. ... one for the LAN and one for the DMZ. ...
      (Security-Basics)
    • Re: Hardware firewall and DMZ machine - put what services where?
      ... Separate every service you want to provide to the outside world from the ... firewall - really. ... Set that up (it supports a DMZ, and VPN tunnels, and lots more) and ...
      (comp.os.linux.security)
    • Re: [fw-wiz] segmentation of DMZs
      ... public as well as private boxes. ... In fact, separate zones can make some things easier, for instance when ... as they pass through the firewall, so that the response always passes ... "open ports x,y,z and 1024-65535 in both directions", etc. ...
      (Firewall-Wizards)
    • Re: Secure Network Design (DMZ, LAN, etc)
      ... separated from the dbs by a firewall - transparent or router (different ... Secure Network Design ... > then why have a separate network? ... > switch. ...
      (Security-Basics)