Re: PIX firewalling web servers

From: Wolfgang Kueter (wolfgang_at_shconnect.de)
Date: 07/23/04


Date: Fri, 23 Jul 2004 18:41:37 +0200

Daniel Foster wrote:

> Hi,
>
> We need to run a firewall in front of our web servers.

- Why?
- What kind of 'firewall'? Packet filter or proxy?

> They are on
> multiple subnets, so the solution would seem to be to have the internet
> connection coming into a perimeter router, then to the firewall, then to
> an internal router and out to the servers.

Ever thought of using VLAN's?

> I'm having a bit of
> difficulty finding any examples of this configuration, although it must
> be in use a lot. Could anyone run through the specifics or provide an
> example configuration? If possible I'd like to avoid running NAT and PAT.

The PIX is not a router.

Wolfgang

-- 
A foreign body and a foreign mind
never welcome in the land of the blind
Peter Gabriel, Not one of us, 1980


Relevant Pages

  • Re: Do i need a FW?
    ... If you have a router and you do not host any web servers, FTP server, ... >>that appears to do a good job but still i wonder if I need a firewall? ... > ISP antivirus won't protect you from worms like Blaster, ...
    (comp.security.firewalls)
  • Re: VPN through a firewall
    ... > There is natting going on in both router and firewall ... > At work there is a similar setup. ... A foreign body and a foreign mind, ...
    (comp.security.firewalls)
  • Re: DMZ When to use
    ... > Router ... If you place the public servers there outside the firewall, ... A foreign body and a foreign mind, ...
    (comp.security.firewalls)
  • Re: Just venting (totally OT)
    ... the ame router to get access to the net! ... I'm paranoid about opening up my firewall "just in case..." ... not visiting dodgy Websites. ... The protection that it does supply is also provided by ...
    (uk.people.support.depression)
  • Re: Just venting (totally OT)
    ... how long it plays for because it's all been ripped on to hard disc ... the ame router to get access to the net! ... I'm paranoid about opening up my firewall "just in case..." ... The protection that it does supply is also provided by ...
    (uk.people.support.depression)