Re: External/DMZ/Internal with two firewalls?



<te@xxxxxxxxxxxxxx> wrote in message
news:1143031550.293290.30020@xxxxxxxxxxxxxxxxxxxxxxxxxxxxxxx
This is the first time I have seen this and I was curious on the
feedback on this configuration...

I'm at a new gig and they have their network setup with two external
firewalls (active/passive) for redundancy, then their DMZ, then another
pair of firewalls before getting into the Internal network.

I have always just seen one set of firewalls, not two. It has made
trouble shooting a complete nightmare, because they do double NAT'ing.

I have read a thing or two that "maybe" this might be something you
would do if you used two different vendors to protect against a 0-day
exploit, but it seems a little odd to me.

I just thought I would ask the experts.

Thanks



It may offend some, but in my experience I've come to know a single firewall
supporting multiple interfaces as a 'Modern DMZ' whereas having two or more
firewalls inline with each other is what is/was referred to as a
'Traditional DMZ' with the network in between known as the perimeter
network.

--
Best regards, from Don Kelloway of Commodon Communications
Visit http://www.commodon.com to learn about the "Threats to Your Security
on the Internet".


.



Relevant Pages

  • Re: What is DMZ?
    ... DMZ is in computer security terms a network ... nor the internal network, but somewhere in between. ... using two firewalls you add another layer of security. ... between the internal network and the compromised host. ...
    (comp.security.firewalls)
  • RE: [fw-wiz] Firewalls v. Router ACLs
    ... people to take in consideration in network design and layout. ... here and the old firewalls list often emphasized an approach that avoided ... The logging alert features alone turn this layer into a IDS as ... > An appropriately sized router will not have any performance problems. ...
    (Firewall-Wizards)
  • [fw-wiz] IDS/IPS and LOGS
    ... nasty behavior is happening on your network (where your network is ... easily turn your IPS into a big denial of service attack. ... My guess is that most of the Worlds firewalls and IDS/IPS only have half ... I noticed that there is a big emphasis on log parsing while there should ...
    (Firewall-Wizards)
  • Re: Establish persistant outbound connection for covert application
    ... which firewalls are running etc.) and then communicate its ... the actual network layer. ... They do have 2 network interfaces in case I want to chain them between a PC ... They also have a wireless interface so I can hook into the machine if I am ...
    (Security-Basics)
  • Re: Going meta (was RE: [fw-wiz] Ok, so now we have a firewall...)
    ... but today's firewalls let too much stuff back ... > why people feel they need to compromise. ... Last spring we completely re-engineered the network for a large school ... All these segments are set up on separate VLANs and communicate with each ...
    (Firewall-Wizards)