RE: Extending the DMZ



Instead of putting the server itself on the DMZ, put a proxy
on the DMZ that relays (only) the needed services to the internal
blade server.

David Gillett


-----Original Message-----
From: CORP John Porter [mailto:jporter@xxxxxxxx]
Sent: Wednesday, October 15, 2008 7:58 AM
To: security-basics@xxxxxxxxxxxxxxxxx
Subject: Extending the DMZ

We have an ASA with a separate interface for the DMZ.
Connected to that interface is a layer 2 switch, and then the
DMZ servers. The Windows guys, working with Application
development, have created a new server, in a blade center.
The blade center has a layer 3 switch built in, which is
connected to our core switch with a 4 port Etherchannel. Now
they want the server they built made available on the
internet. I have told them that the server must be moved to
the DMZ, but they are reluctant to do that because they
already built it on an internal Blade Server. They want me to
create a VLAN on the layer 3 switch and connect 1 port from
the layer 3 switch to the layer 2 DMZ switch, so the server
will be available on the DMZ.

This seems like a very bad idea to me:
- Someone can mis-configure the server and end up with it
acting as a router to pass traffic between the DMZ and inside network
- The layer 3 switch is going to route traffic between the
new VLAN and the inside network
- Even if I manage to lock things down so that it works,
there may be other problems/exploits that make this a bad idea.

Am I just being paranoid, or is this definitely a bad idea?




Relevant Pages

  • RE: fedora-list Digest, Vol 6, Issue 266
    ... Re: OT: Setting up a forwarding mail domain in DMZ without ... Re: Sound Problem ... downloaded the yum.conf for fedora from Redhat's website. ... Server: Fedora.us Extras ...
    (Fedora)
  • Extending the DMZ
    ... We have an ASA with a separate interface for the DMZ. ... interface is a layer 2 switch, ... want the server they built made available on the internet. ...
    (Security-Basics)
  • RE: Webserver on a DMZ still needed?
    ... Certainly your suggestion to have a email server in a DMZ but still have ... having the exchange server on the internal LAN with only the smtp ports ... Talking of the financial cost of setup by the book vs the security cost ...
    (Security-Basics)
  • Re: Man gets nine years for spamming
    ... > I don't think we've ever had web access. ... > connect to an inner server where you logged in and actually did stuff. ... We have 12 DMZ interfaces. ... the DMZs and in between the Internet routers and the first ...
    (alt.computer.security)
  • RE: [fw-wiz] Backup exec agent in dmz
    ... named.conf file and the zonefiles off the the NT box in the DMZ. ... on the Apache server, ... backup tape library in this DMZ and backup all your servers to the new DMZ. ... what do you really need to back up on the DNS and web servers? ...
    (Firewall-Wizards)

Quantcast