Re: Security in DMZ itself

From: x y (jamescagney90210@excite.com)
Date: 04/29/02


From: "x y" <jamescagney90210@excite.com>
Date: Mon, 29 Apr 2002 14:44:26 GMT

Yes, I would think most modern medium-quality switches should give you the
ability to set up VLANs, though personally I would feel more secure with
different network cards in the FW-1 box to create different physical LANs.
Otherwise, if you're using the switch to create VLANs, I think you're
relying on the switch for the security instead of the firewall. If someone
hacked into one of the boxes and used, say, SNMP or telnet to reconfigure
your switch, you'd be owned. It sounds unlikely, but possible. I guess you
just have to do what you can with what you can afford to get the most
security you can.

"Greg Hennessy" <nntp@NOSPAM.cmkrnl.cix.co.uk> wrote in message
news:vd8qcugtronlbuj6dvhvg6mlaskujfh8gj@4ax.com...
> On Mon, 29 Apr 2002 11:08:05 +0200, "Sjoerd" <skrol@inter.nl.net> wrote:
>
>
> >Any ideas to accomplish this?
>
> Yes, you can keep them all on the same network and configure up per port
> private VLANS for each server.
ev'rything's all right.



Relevant Pages

  • Re: VLAN Help
    ... clear how your network is setted up. ... the remote office LAN and add a port which will connect to this LAN ... Once you do that you have to add a tagged port to the 2 VLANS (yours ... > Our network center runs the same switch but the Layer 3 Version. ...
    (Security-Basics)
  • RE: Rogue IP Address
    ... capability that you paid for when buying the switch, ... someone will holler about his network not working. ... prospectus based upon the core principle concepts of security. ... This ALL INCLUSIVE curriculum utilizes lectures, case studies and true hands-on utilization ...
    (Security-Basics)
  • Re: Clueless firewall configuration ?
    ... One question I would ask is, "How does the switch respond if the ... between the vlans (oh and we are a big production site that relies on ... Concerned about Web Application Security? ... Download FREE whitepaper on how a managed service can ...
    (Pen-Test)
  • RE: RE: Pros and against using Multiple firewalls in a network ru nning on Win2k Advanced server.(re
    ... Pros and against using Multiple firewalls in a network ru nning on Win2k Advanced server.(repost.. ... slackware for my server setups, so I haven't run into any problems on that ... that is usually handled by a switch. ... The vlans were all set up before I came ...
    (Focus-Microsoft)
  • Re: probably an easy routing question, so please help
    ... I've just realized that VLANs don't just divide subnets, ... router) I won't need to use a Layer 3 switch at all. ... both /28s are configured on the same Enet port, with proxy ARP enabled. ...
    (comp.dcom.sys.cisco)