Re: Extending the DMZ



Is it feasible to add another Ethernet interface to the server, connect that to the DMZ, and disable routing between the two interfaces?
----- Original Message ----- From: "CORP John Porter" <jporter@xxxxxxxx>
To: <security-basics@xxxxxxxxxxxxxxxxx>
Sent: Wednesday, October 15, 2008 9:58 AM
Subject: Extending the DMZ


We have an ASA with a separate interface for the DMZ. Connected to that
interface is a layer 2 switch, and then the DMZ servers. The Windows
guys, working with Application development, have created a new server,
in a blade center. The blade center has a layer 3 switch built in, which
is connected to our core switch with a 4 port Etherchannel. Now they
want the server they built made available on the internet. I have told
them that the server must be moved to the DMZ, but they are reluctant to
do that because they already built it on an internal Blade Server. They
want me to create a VLAN on the layer 3 switch and connect 1 port from
the layer 3 switch to the layer 2 DMZ switch, so the server will be
available on the DMZ.

This seems like a very bad idea to me:
- Someone can mis-configure the server and end up with it acting as a
router to pass traffic between the DMZ and inside network
- The layer 3 switch is going to route traffic between the new VLAN and
the inside network
- Even if I manage to lock things down so that it works, there may be
other problems/exploits that make this a bad idea.

Am I just being paranoid, or is this definitely a bad idea?



Relevant Pages

  • Extending the DMZ
    ... We have an ASA with a separate interface for the DMZ. ... interface is a layer 2 switch, ... want the server they built made available on the internet. ...
    (Security-Basics)
  • Re: does ethernet bonding require a switch to be of a specific type?
    ... I think the switch supports VLANs. ... But I'm planning to not use the VLAN functionality. ... If you only ever talk to one box, then only one interface would ever be used, no matter how many you bond together. ... 802.3ad is intended more for trunking, so it would be a great choice for a dedicated firewall box that handles lots of IP addresses and needs a huge network throughput, but I wouldn't recommend it for just an end-point server. ...
    (comp.os.linux.misc)
  • RE: Extending the DMZ
    ... Instead of putting the server itself on the DMZ, ... Connected to that interface is a layer 2 switch, ... already built it on an internal Blade Server. ...
    (Security-Basics)
  • Re: Exchange 2003 Routingproblem
    ... Also erstmal mein Beileid zu deiner Idee den selben Server mit einem ... Da kannst du dir die DMZ ja gleich schenken und einfache Portforwardings ... Jedes Interface braucht das jeweilige Gateway im Segment und das Routing ... Next by Date: ...
    (microsoft.public.de.exchange)
  • Re: Extending the DMZ
    ... Analyse how server is secure. ... interface is a layer 2 switch, and then the DMZ servers. ...
    (Security-Basics)