Re: VLANS in a DMZ - good idea?

From: Greg Hennessy (me_at_privacy.org)
Date: 01/26/05


Date: Wed, 26 Jan 2005 17:22:44 +0000

On 26 Jan 2005 05:40:10 -0800, dgunner@lycos.co.uk (Damian) wrote:

>I am looking to setup a new perimeter network for a client and am
>contemplating the following setup as they have a spare L3 routing
>switch to hand.
>
>
>The L3 switch will have each port assigned to a separate network, one
>for mail, one for the extranet and one for the outbound proxy.

Using VLANS to provide logical and physical seperation in a DMZ(s) is an
excellent idea as long as all the configured VLANS are at the same trust
level on the switch.

If its a crisco take a look a configuring up private VLANs on each
endpoint.

http://www.cisco.com/en/US/about/ac123/ac114/ac173/ac222/about_cisco_packet_feature09186a0080142deb.html

greg
 

-- 
Yeah - straight from the top of my dome 
As I rock, rock, rock, rock, rock the microphone 


Relevant Pages

  • Re: All these gals were given military funerals with honors per Lincoln
    ... was working on the battle field of Shiloh, ... Hey "GLOBALIST" - good to have you out from under that rock of yours. ... Philadelphia and on the other hand when pressed for details talk about ... Clearly "GLOBALIST" remains steadfast under that rock of his rather than to explain to us first, his "bait and switch" and second, how it is that he finds those Sisters of Charity in Philadelphia were in fact in harm's way. ...
    (soc.retirement)
  • Re: Well, TNA is well on the way to Suckville...
    ... Where's Daniels? ... Where was Hardy? ... (I had to switch to 30 Rock some of the time, ...
    (rec.sport.pro-wrestling)
  • Well, TNA is well on the way to Suckville...
    ... Where's Daniels? ... Where was Hardy? ... (I had to switch to 30 Rock some of the time, ...
    (rec.sport.pro-wrestling)
  • Re: OT: MSs new campaign against piracy...
    ... Money to burn, that lot. ... My rock was horrible and rough to hold, so I threw it in the bin. ... Ring an MS help desk and say that you can't find the 'on' switch. ...
    (uk.comp.sys.mac)
  • Re: probably an easy routing question, so please help
    ... I've just realized that VLANs don't just divide subnets, ... router) I won't need to use a Layer 3 switch at all. ... both /28s are configured on the same Enet port, with proxy ARP enabled. ...
    (comp.dcom.sys.cisco)