Re: Network Re-design



Hi,

I think that the best for you would be to set up serveral network segments. At least one for the DMZ with all your servers and one for the workstations, each in a different subnet. For the security, also think of using site-to-site VPN between your two sites.

With your amount of workstations I would advise you to buy a strong appliance box for routing / firewalling / VPN and eventually antispam, antivirus, intrusion prevention, URL filtering and so on.

Regards,

Jeremy Saintot

Tornado a écrit :
Hello All,

We are in process of redesigning our whole network from security
perspective. We have around 400 workstations with around 20 servers. These are located between 2 locations and connected with dedicated P2P link.
None of the servers are facing the internet at the moment.But in the forthcoming months we might have some servers facing the internet.
I wanted to know what are the considerations we need to take
when taking such a crtical activity. Are there any good resources on the net
which help us to get started?

Thanks in advance.

----------------------------------------------------------------------
Click for free info on criminal justice degrees and make $150K/ year
http://tags.bluebottle.com/fc/CAaCMPJnQhOgsuK503hrQ7H84DhnARet/





Relevant Pages

  • How NOT to provide external name resolution on win2k3?
    ... We have a domain with 2 windows 2003 servers as domain controllers that are ... workstations point to these 2 servers as their preferred dns servers. ... We recently discovered that the workstations can resolve internet addresses ...
    (microsoft.public.win2000.dns)
  • Re: How NOT to provide external name resolution on win2k3?
    ... The best way to "control" internet access is via Proxies. ... If you want to ensure your internal DNS servers don't forward, ... > workstations point to these 2 servers as their preferred dns servers. ...
    (microsoft.public.win2000.dns)
  • Re: Question Servers with 2 Nics and Lan/Internet
    ... My plan is to enable the 1000Mbps nics on our servers and a few of the ... workstations, all of which are currently only using their 100 Mbps ... How to Configure OEx for Internet News ...
    (microsoft.public.windows.server.networking)
  • Re: Allowing access to IP/MAC pairs only
    ... We have feeBSD 6.2 machines with local subnets on the servers and would like to allow access to the internet only for workstations with exact IP/MAC pairs and deny access for not predefined pairs. ...
    (freebsd-stable)
  • Re: Fixed IP address
    ... We assign fixed IP addresses to lots of workstations and servers and have no problems accessing the Internet. ... However, when I set the Lan connection property to use a fixed IP address, the internet connection does not work. ...
    (microsoft.public.windows.server.setup)