Advise: protect LAN from two non-trusted networks

From: Bob Walker (r042wal_at_no.spam.sympatico.ca)
Date: 09/30/03


Date: Mon, 29 Sep 2003 21:02:16 -0400

I am working on a project that involves merging a Federal network with a
local police LAN. Before the Federal network will merge, the local LAN has
to be secured with an EAL4 rated firewall appliance.

The local police LAN is only 8 workstations. The LAN is connected to the
Internet with a router. The LAN is also connected to the Provincial network
which is also not secure. I have to secure this network before the federal
network is merged and I don't have a lot of money at my disposal.

I would like to use Netscreen appliances such as the 5XP, but near as I can
determine, I am going to need an appliance to protect the LAN from the
Internet and an appliance to protect the LAN from the Provincial network.

Some police agencies have used CISC PIX 500 series appliances, and it has
also been suggested that I consider an appliance with two untrusted
interfaces although I have not found any.

I am open to any suggestions.

TIA



Relevant Pages

  • Re: Advise: protect LAN from two non-trusted networks
    ... Before the Federal network will merge, the local LAN has ... > to be secured with an EAL4 rated firewall appliance. ... > interfaces although I have not found any. ...
    (comp.security.firewalls)
  • Re: Loss of Connectivity on Only One PC on a LAN
    ... When you ran the Network Setup Wizard, ... The original setup of the LAN was done entirely by the user of the other PC on that LAN in July. ... I use a LAN connection which consists of two PCs each connected to a Linksys BEFSR 41 Router. ...
    (microsoft.public.windowsxp.network_web)
  • Re: Advise: protect LAN from two non-trusted networks
    ... Thanks Dean. ... Before the Federal network will merge, the local LAN ... I am going to need an appliance to protect the LAN from the ...
    (comp.security.firewalls)
  • Re: TCPIP - Ping tool
    ... Strangely enough the answer was under your nose all along, namely PING. ... If your "internal network" corresponds to a Local Area Network (LAN), ... assume the subnet address for your LAN is 192.168.10.0 and the subnet mask ...
    (bit.listserv.ibm-main)
  • Re: Firewall and DMZ topology
    ... attacker cannot spread his influence across the network. ... If the DMZ resides between the public Internet and the ... Should the DMZ be behind the LAN and not split off at the firewall, ... > The Gartner Group just put Neoteris in the top of its Magic Quadrant, ...
    (Security-Basics)