Re: DMZ (De-militarized Zone)

From: John (jwholmes_at_earthlink.net)
Date: 12/02/03


Date: Tue, 02 Dec 2003 07:06:01 GMT

On Mon, 01 Dec 2003 05:27:24 -0800, Arman wrote:

> Hi Everybody
>
> I am prepared to create a DMZ network for all my testings and also a
> Safe zone for my file servers and so on! Currently inside our office
> there are several computers connected to a hub and then through a
> Cisco 800 series router which gets configured by our ISP! This router
> is capable of DMZ but it only has one cable port which is useless to
> me because the whole idea of DMZ is to create two seprate networks
> where the two can not talk to each other! Money is not exactly an
> issue here, but maximum security is my main concideration, so throw
> the best options at me as well as the cheap solutions too :P
>
> I would like to know your suggestions on whether im better of going
> ahead with hardware firewall (Cisco Routers for example) which is
> caplable of DMZ the extra ports to seprate my DMZ from my safe zone or
> i should go ahead with Software Firewalls (Dedicate a Linux pc with a
> firewall software and 3 NIC) to used instead of a Router/Firewall? I
> know that if i use the software firewall solution then i dont have to
> do anything to my router or get the ISP guys to configure anything for
> me so thats another plus for the Software solution! if You think
> hardware firewall/router is the way to go plz tell me what brands or
> types are good for a medium size company? and also what softwares for
> the PC if thats what you think i should do?
>
> Your help is appriciated

First of all, there is no "safe zone" unless it is a physically separate
network. Since you say they should not be able to talk to each other that
is exactly what you should do. Since you seem to want an outside, dmz
(actually a screened network but everyone calls it the wrong thing these
days) and inside you can go either way. The best option for security is to
hire a competent security guy and have them setup whatever they know the
best. Not even a great firewall is worth a damn if you misconfigure it.

Wolfgang is wrong about wirecutters being the only hardware firewall. A
good vault door will do the trick almost as well as cutting the cable. ;)

Seriously, there are lots of choices. The right one is the one you feel
comfortable setting up and running. People will try to tell you X sucks or
Y is great but if you can't run it, it is a security risk.
 

-- 
___________
John Holmes
jwholmes@earthlink.net


Relevant Pages

  • Re: Host Computer with ICS cannot be accessed
    ... You read my mind on the router thing. ... My home network is a piece of cake... ... >>firewall settings, not that I've found so far, but I'll keep looking. ... and we couldn't get file sharing working until ...
    (microsoft.public.windowsxp.network_web)
  • Re: share my printer between 2 computers and surf with 2 computers at same time
    ... The main choice you have to make is whether to have the router include wireless capability or not. ... Because wireless routers for home use are relatively inexpensive these days, I'd suggest buying a wireless router even if you don't initially intend to use that capability. ... If you already have a UTP cable going between upstairs and downstairs, you can use that to have a wired network. ... caused by 1) a misconfigured firewall; ...
    (microsoft.public.windowsxp.network_web)
  • Re: share my printer between 2 computers and surf with 2 computers at same time
    ... The main piece of hardware you need to buy is a router. ... Because wireless routers for home use are ... you can use that to have a wired network. ... caused by 1) a misconfigured firewall; ...
    (microsoft.public.windowsxp.network_web)
  • RE: [Full-Disclosure] Re: January 15 is Personal Firewall Day, help the cause
    ... the>outside world which are in response to packets originating from ... to drop in a little Trojan, your whole network can be compromised. ... NAT router works at Layer 3. ... You still need a personal firewall or ...
    (Full-Disclosure)
  • Ang: RE: Firewall and DMZ topology
    ... Network Engineer ... Subject: Firewall and DMZ topology ... > The Gartner Group just put Neoteris in the top of its Magic Quadrant, ...
    (Security-Basics)