Re: DMZ traffic (was Please help ! need to check IIS volunrabilities.)

miguel.dilaj_at_pharma.novartis.com
Date: 11/28/04

  • Next message: Seth Jackson: "Windows Messenger Pop-up spam"
    To: security-basics@securityfocus.com
    Date: Sun, 28 Nov 2004 20:48:55 +0100
    
    

    Hi!

    Well, what comes to mind is putting the DB in the DMZ (or in another DMZ
    with other restrictions, if needed) and allowing the clients in the LAN to
    connect to it for updates, etc.
    I mentioned that connections starting from the DMZ to the LAN must be
    forbidden, but the opposite can be allowed of course!
    The fact that the DB is in a minicomputer doesn't affect where you want to
    put it in the network, you don't need to have 2 and synchronize, just put
    it in the proper place for the use it's intended (and have backups ;-)
    Cheers,

    Miguel Dilaj (Nekromancer)

    <sf_mail_sbm@yahoo.com>
    26/11/2004 15:03

     
            To: security-basics@securityfocus.com
            cc: (bcc: Miguel Dilaj/PH/Novartis)
            Subject: Re: DMZ traffic (was Please help ! need to check IIS volunrabilities.)

    >>5) Is the configuration of the DMZ "watertight"? (In particular:
    >>connections STARTING in the DMZ must be forbidden).
    >
    >How would you prevent this in a case were a webserver needs to access a
    production db in the Internal network for >queries/updates?
    >
    >You might propose to use another db in the DMZ, and perform regular
    synchronisations - but what if the db is >being held on a minicomputer
    (cost issue))?


  • Next message: Seth Jackson: "Windows Messenger Pop-up spam"

    Relevant Pages

    • Configuring NTP
      ... I've a windows 2003 DC in my LAN and I want it to synchronize with a NTP ... Linux server which is in my DMZ. ...
      (microsoft.public.windows.server.general)
    • Re: Unable to join AD domain from DMZ network
      ... > the captured traffic between the server in DMZ to the DC from internal ... >> unless you lock it down to a specific port. ... >>> authentication from DMZ to 2003 AD internal network. ...
      (microsoft.public.windows.server.active_directory)
    • Re: Near and far dmz (is this model secure)
      ... I think that your boss is right, the Exchange servers should be on the ... in a DMZ via VPN tunnel. ... connections from the DMZ to the internal network, ...
      (comp.security.firewalls)
    • Re: Unable to join AD domain from DMZ network
      ... To me that points to something outside the machine (Firewall most likely culprit) ... > the captured traffic between the server in DMZ to the DC from internal ... >>> authentication from DMZ to 2003 AD internal network. ...
      (microsoft.public.windows.server.active_directory)
    • RE: Firewall and DMZ topology
      ... purpose of a DMZ is to segment machines from your internal network whilst ... Subject: Firewall and DMZ topology ... I would like to set up a SOHO network with a firewall and DMZ for mostly ... Evaluating SSL VPNs' Consider NEOTERIS, chosen as leader by top analysts! ...
      (Security-Basics)