Re: PIX firewalling web servers

From: Lars M. Hansen (badnews_at_hansenonline.net)
Date: 07/26/04


Date: Mon, 26 Jul 2004 12:30:59 GMT

On Mon, 26 Jul 2004 10:35:29 +0100, Daniel Foster spoketh

> > Ever thought of using VLAN's?
>
>Care to expand on that? How would using a VLAN help me to firewall the
>web servers?
>
>There's no concept of a DMZ or anything in this scenario - the only
>things behind the firewall are servers.

Well, using VLANs will combine the internal routers and switches. You
can simply create a VLAN for each subnet in use by your servers, and the
switch will take care of the routing between the VLANs for you. By
adding packet filtering on the switch, you may also reduce some of the
overhead of filtering outbound traffic on the firewall.

Lars M. Hansen
www.hansenonline.net
Remove "bad" from my e-mail address to contact me.
"If you try to fail, and succeed, which have you done?"



Relevant Pages

  • Re: Controlling access to MSTSC.exe
    ... to get through the windows firewall. ... static configuration by using VLANS in conjunction with a VLAN Policy Server ... > programs where I will need the ability to restrict by ... >>> level policy (i.e. who can connect via remote desktop to the servers). ...
    (microsoft.public.windowsxp.setup_deployment)
  • Re: [fw-wiz] Worms, Air Gaps and Responsibility
    ... isolate desktop and laptop systems from servers using switches and the firewall ... Cisco offers "Private VLAN" capabilities in their layer 2 switches. ... VLAN you can designate ports as private or public. ... Using a firewall and defined interfaces that can be adequately ...
    (Firewall-Wizards)
  • Re: Connecting to Multiple networks
    ... Well to be honest they are not really fussed about a firewall, ... PIX and stop the VLan Nonsence. ... >>> firewall then public facing servers and then firewall then private data ... Everyone else here are Cisco network engineers and have Unix ...
    (microsoft.public.win2000.networking)
  • Re: Bridges
    ... > carrying tagged VLAN traffic then? ... could be pretty useful to be able to bridge vlaninterfaces together. ... asked to build a single firewall for a whole rack of servers. ...
    (freebsd-arch)
  • RE: Slow user logon on Terminal server after migration to Windows 2003
    ... The Terminal Servers are 2000 or 2003. ... "Inside the firewall zone" means that the Citrix Servers have a firewall ... available RPC ports? ...
    (microsoft.public.windows.server.active_directory)