Re: dns on firewall

From: Heinz Ekker (hekker-usenet@hoppa.la)
Date: 02/28/02


From: Heinz Ekker <hekker-usenet@hoppa.la>
Date: 28 Feb 2002 00:01:47 GMT

Bruno Wolff III <bruno@cerberus.csd.uwm.edu> wrote:

> The reason for worrying about the firewall itself being compromised, is
> that it becomes easier to use your network for outbound attacks, since
> your filtering rules can be compromised.

Not only that, but because all your in- and outbound traffic will run
via the firewall, the hacker can cause more grieve by sniffing or
manipulating that traffic.

If you take precautions, like restrictions on communication between the
DMZ servers or using different root passwords on your systems it should
be a lot easier to recover from an attack on one of your servers.

> Ideally each service should have its own machine(s), but the cost of
> doing this might be higher than that of taking the risk of running
> multiple services on the same box.

That's recommendable not only for security reasons, but also for
optimized performance. A J2EE application server and BIND competing for
RAM is no fun at all. Increased performance consumption of one service
doesn't affect others, etc. etc.

Running exposed services, like web or DNS on the same box as the - say,
customer database is suicide.

he



Relevant Pages

  • Re: dns on firewall
    ... >> The reason for worrying about the firewall itself being compromised, ... >> that it becomes easier to use your network for outbound attacks, ... servers isn't likely to be the case. ...
    (comp.os.linux.security)
  • RE: [fw-wiz] Log checking?
    ... >> It's for this reason I always setup IDSinside the firewall. ... >> It also has the nice side effect of monitoring what people inside ... that the system may occur is by setting an email relay on every servers ...
    (Firewall-Wizards)
  • Re: false portscan alarm
    ... What is the reason of that treffic? ... and the browser and/or the "personal firewall" had decided to close those ... which each have a local source port above 1024 opened outgoing to port 80 ... I've had a dig through my own PIX logs, and while there is nothing for today ...
    (comp.security.firewalls)
  • Re: OT: disabling APIs to prevent keystroke logging
    ... they have taken to heart some of the advice offered here. ... as I've got good reason to say it.) ... Being concerned about security is never stupid, ... I'm not a huge fan of firewall software that does application level ...
    (alt.sys.pc-clone.dell)
  • Re: ZoneAlarm Pro vs Outpost Pro?
    ... This is not the reason, ... > First there is a difference between opinions and facts. ... I see no reason why the Windows firewall shouldn't be called a real ... Most of us here are aware of how personal firewall outbound control can be ...
    (comp.security.firewalls)