getting routes from internet facing routers



Hi All

I've always heard as best practice that you should keep your internal
routes off external facing routers. And I've also heard that it's
possible to get routes from a router/firewall facing the public domain
without having to login to it. Can anybody explain (or give an
example) of how this is achieved ? Is it by using ICMP ? Does this
only apply to routers using dynamic routing or does it also apply to
static routes ?

Thanks in advance !
M

------------------------------------------------------------------------
Securing Apache Web Server with thawte Digital Certificate
In this guide we examine the importance of Apache-SSL and who needs an SSL certificate. We look at how SSL works, how it benefits your company and how your customers can tell if a site is secure. You will find out how to test, purchase, install and use a thawte Digital Certificate on your Apache web server. Throughout, best practices for set-up are highlighted to help you ensure efficient ongoing management of your encryption keys and digital certificates.

http://www.dinclinx.com/Redirect.aspx?36;4175;25;1371;0;5;946;e13b6be442f727d1
------------------------------------------------------------------------



Relevant Pages

  • Re: ISPs?
    ... Our border routers run Quagga but we are in the ... We are using Network Appliances from portwell as ... will receive full routes. ... my internal route server from distributing the routes into the network. ...
    (freebsd-isp)
  • Re: routing problem
    ... setting up routes after the connection is made. ... Here we hit the problem of mixing ISA and RRAS. ... > OK, unfortunately, I have to use the DC's as VPN routers. ...
    (microsoft.public.windows.server.networking)
  • Re: Load-balancing across four T1s on 2 routers
    ... Actually the L3 switch will only see 2 equal-cost routes. ... The firewall's' default gateway will be that layer-3 switch. ... also on 2 routers on the ISP's site. ...
    (comp.dcom.sys.cisco)
  • Re: bridging
    ... > establish two routes over the two separate physical devices. ... but it is two routes with the *same* physical device. ... Most all commercial grade routers have at least ... and the router determines which serial port the traffic is to go out of. ...
    (microsoft.public.win2000.networking)
  • Re: IPCOP OPENVPN side by side with router VPN
    ... the IPCOP distro doesn't allow it from the config webpage... ... your static routes should override anything the routers get via ... Secondly, if your ISP is using 10.* as part of its management network, ...
    (comp.os.linux.networking)

Quantcast