Firewall and VLAN security design

From: Ahmed Ameen (ahmedameen_at_gmail.com)
Date: 10/31/04

  • Next message: kyle: "Re: possible rooted systems"
    Date: Sun, 31 Oct 2004 02:45:44 +0200
    To: security-basics@securityfocus.com
    
    

    Hi All,

    Currently we are redesigning our LAN to include a DMZ zone, and we
    need to reach the best security design.
    The available equipments are:
    1-PIX with 3 NIC's
    2-L3 Switch
    3-N-IDS

    My preliminary design is as follows

    Internet
        |
        |
    --------
    |PIX |____DMZ
    | |
    --------
        |
        |
       LAN

    Internet
        |
        |
    --------
    |NIDS |____DMZ
    | |
    --------
        |
        |
       LAN

    Internet VLAN1
        |
        |
    ---------------
    |L3 Switch|____DMZ VLAN2
    | |
    ----------
        |
        |
       LAN VLAN3

    My Questions would be:
    Is it ok to use a multi homed firewall, or should I conceder 2
    physical firewalls, what would be the threat of using one.

    Is VLAN segmentation enough to segment between the internet, DMZ and
    the internal network, or should I also use different switches for
    each, and be connected through the firewall.

    Thanks

    Firewall and VLAN security design


  • Next message: kyle: "Re: possible rooted systems"

    Relevant Pages

    • Re: How save is a Windows PC on a Linux network.
      ... firewall between the dialup and the internal lan. ... Being of sound mind and body, I never surf with the Windows machine and ... Assuming you trust your firewall, and you know what's running on the ... I have to have it on the lan to access the Linux servers but sometimes it ...
      (comp.os.linux.misc)
    • Re: OWA
      ... 'Thats good news at least about the firewall. ... Tried them both earlier and same error message - 403. ... get ths same error message in and outside of the LAN? ...
      (microsoft.public.backoffice.smallbiz2000)
    • Re: Wohin mit dem OpenVPN Server?
      ... Ich geb dem Server eine öffentliche IP und setze ihn in die DMZ, ... Adresse über die Firewall von der DMZ aus ins LAN verbinden... ... Ein kompromittierter VPN-Server ...
      (de.comp.security.firewall)
    • Re: [SLE] Firewall zones
      ... Looking at the firewall configuration in Yast, ... My network card is assigned its IP address by the router using DHCP. ... It connects to the LAN and to the router; the router in turn talks to the ... All the systems on the LAN are supposed to have the same firewall protection, ...
      (SuSE)
    • Adjunto 24k ! Error conexión remota 2003 SBS
      ... He habilitado la conexión remota de sbs 2003 para trabajadores que acceden ... Servidor 2003 SBS con 1 tarjeta de red, IP de clase C, conectada a switch ... Internamente desde Lan funciona todo a las 1000 maravillas. ... Problemas del firewall? ...
      (microsoft.public.windows.server.sbs)