Re: Firewall Solution for Web Server

From: Berk S. Daemon (someone@somewhere.com)
Date: 08/23/02


From: "Berk S. Daemon" <someone@somewhere.com>
Date: Fri, 23 Aug 2002 20:53:55 GMT


"JP" <pangjoe@rogers.com> wrote in message
news:VAp99.24638$bu81.721@news02.bloor.is.net.cable.rogers.com...
> Looking for a cheap firewll solution for a hosting web server which has to
> make queries to a production server in the internal LAN. It would be
ideal
> to use a hardware firewall with one WAN and two LAN interfaces so that a
DMZ
> could be set up.
>
> Just want to see if I can use inexpensive ADSL routers such as Netgear,
> D-Link and Linksys for security.
>
> Internet - <Dlink DI-704> - WebServer - <Dlink DI-704> - Internal LAN
>
> The first Dlink will have only port 80 opened for the WebServer. All
other
> protocol will be blocked. The second one will allow the WebServer to
access
> the Internal Lan by FTP. All other address IP's and protocols will be
> blocked.
>
> I know it is not a secure solution but just want to know if it would still
> provide some firewall function. Otherwise, I would consider building a
> Linux firewall. Any comments?
>
> Cheers,
>
> JP

I wouldn't use the same box or device for a DMZ. Realisticly, those should
be physically seperate.

As for Linux firewall, personally I'd do OpenBSD instead. Be it NAT + Packet
Filtering or Transparent Bridging Firewall in OpenBSD.



Relevant Pages

  • Re: Firewall Solution for Web Server
    ... > Looking for a cheap firewll solution for a hosting web server which has to ... > make queries to a production server in the internal LAN. ... > provide some firewall function. ...
    (comp.security.firewalls)
  • Firewall Solution for Web Server
    ... Looking for a cheap firewll solution for a hosting web server which has to ... make queries to a production server in the internal LAN. ... to use a hardware firewall with one WAN and two LAN interfaces so that a DMZ ...
    (comp.security.firewalls)
  • Re: Simple Routing with Redhat 9
    ... > This has been keeping me awake for 3 days now, so I am turning to you for ... > My objective is to set up a simple firewall using iptables using RH9 as my ... > enabled so the workstations on the internal LAN can browse the net. ... The USA Patriot Act is the most unpatriotic act in American history. ...
    (comp.os.linux.networking)
  • Re: Simple Routing with Redhat 9
    ... > This has been keeping me awake for 3 days now, so I am turning to you for ... > My objective is to set up a simple firewall using iptables using RH9 as my ... > enabled so the workstations on the internal LAN can browse the net. ... The USA Patriot Act is the most unpatriotic act in American history. ...
    (linux.redhat)
  • Re: Simple Routing with Redhat 9
    ... > This has been keeping me awake for 3 days now, so I am turning to you for ... > My objective is to set up a simple firewall using iptables using RH9 as my ... > enabled so the workstations on the internal LAN can browse the net. ... The USA Patriot Act is the most unpatriotic act in American history. ...
    (linux.redhat.install)