Re: VM Host with guests on the Internal and DMZ networks



Hi Megan,

A host configured like this would effectively bypass the security devices that create the DMZ rendering the DMZ pointless I think you had it right with the really bad idea. :-)

Best Regards
Mark Sutton

Megan Kielman wrote:
Security Folks,

We want to have a VMWare
host (VMWare Server) that has guest systems on the DMZ and Internal
LAN. To accomplish
this the host would have two interfaces, one on each network. Is this
a really bad idea from a security perspective? What are some ways to
mitigate the risks?

Thanks!
Megan



Relevant Pages

  • RE: Re: Re: VM Host with guests on the Internal and DMZ networks
    ... So are you saying that you should put your HOST in the DMZ. ... NIC and then add and IP Address that would work on the inside network while ... I would question the sysadmins level of competency. ...
    (Security-Basics)
  • Re: DMZ Arguments....
    ... A DMZ is used with a firewall, ... link to the rest of the network. ... A common approach for an attacker is to break into a host that's vulnerable ... the case of a web server, unauthenticated and untrusted users might be ...
    (Security-Basics)
  • [NEWS] SMC Barricades Dodgy "DMZ" Feature
    ... The following security advisory is sent to the securiteam mailing list, and can be found at the SecuriTeam web site: http://www.securiteam.com ... hosts in a DMZ should not be ... able to initiate connections to internal LAN hosts. ... DMZ host be compromised (from having its connected-to-from-the-internet ...
    (Securiteam)
  • Re: DNS inside the DMZ on an 877
    ... the dmz to refer to external DNS servers for hosts outside the DMZ ... any host outside the DMZ. ... permit tcp host 192.168.168.2 host 10.0.0.10 eq 636 ... match access-group name adam ...
    (comp.dcom.sys.cisco)
  • RE: VM Host with guests on the Internal and DMZ networks
    ... DMZ and internal thus crossing our internal firewall....but with vmware ... VM Host with guests on the Internal and DMZ networks ... Attacks local to the guest allow the guest to attack the host. ...
    (Security-Basics)