Firewall Wizards mailing list archives
Re: Flat vs Segmented DMZ's
From: Dave Piscitello <dave () corecom com>
Date: Wed, 06 Nov 2002 14:35:47 -0500
First, I assume you mean "multiple DMZ segments", not "there's a DMZ LANbehind my firewall, then a router, then another LAN"... if correct, then proceed,
if not, ignore... What's the business rationale for segmenting?I know that for a hosting company/IDC, you might segment according to customer needs and feeds - if you have a 100 Mbps into the data center, you may use VLANs and traffic enforcement to give 20 subscribers individualized security policy and a bandwidth commitment.
If you're an enterprise, are you trying to compartmentalize business units? Allocate and prioritize bandwidth across business units or special purposed servers? Unique security policies per DMZ segment?
At 08:28 AM 11/6/2002 -0800, WhtWlf2001 wrote:
I'm hoping to get some feedback (Pros/Cons) from the list members on a Flat vs. Segmented DMZ structure. We currently have about 20 hosts segmented off to 4-5 different DMZ interfaces on a CP firewall. With the exception of having a seperate MGMT DMZ, I'm curious about the benefits/detriments to having this segmented infrastructure. Today we offer only limited webservices (http,ftp,owa) via the web. Thanks in advance for your reply. __________________________________________________ Do you Yahoo!? Yahoo! News - Today's headlines http://news.yahoo.com _______________________________________________ firewall-wizards mailing list firewall-wizards () honor icsalabs com http://honor.icsalabs.com/mailman/listinfo/firewall-wizards
David M. Piscitello Core Competence, Inc. & 3 Myrtle Bank Lane Hilton Head, SC 29926 dave () corecom com 843.689.5595 www.corecom.com _______________________________________________ firewall-wizards mailing list firewall-wizards () honor icsalabs com http://honor.icsalabs.com/mailman/listinfo/firewall-wizards
Current thread:
- Flat vs Segmented DMZ's WhtWlf2001 (Nov 06)
- Re: Flat vs Segmented DMZ's Paul Robertson (Nov 06)
- Re: Flat vs Segmented DMZ's Dave Piscitello (Nov 06)
- Re: Flat vs Segmented DMZ's Mikael Olsson (Nov 06)
- Re: Flat vs Segmented DMZ's Carson Gaspar (Nov 06)
- Re: Flat vs Segmented DMZ's Luca Berra (Nov 21)
- <Possible follow-ups>
- RE: Flat vs Segmented DMZ's Scott, Richard (Nov 07)