Security Basics mailing list archives
RE: Firewall and DMZ topology
From: "David Gillett" <gillettdavid () fhda edu>
Date: Tue, 10 Jun 2003 10:10:38 -0700
-----Original Message----- From: Chris Berry [mailto:compjma () hotmail com] I'm afraid I don't see how that: internet --> Firewall --> Lan internet --> Firewall --> DMZ
Actually, it's internet <-- Firewall <-- LAN internet --> Firewall --> DMZ
would be any more secure than this: internet --> Outer Firewall --> DMZ --> Inner Firewall --> LAN
internet <--> Outer Firewall <--> DMZ <-- Inner Firewall <-- LAN (no more secure, and slightly inefficient
or this: internet --> Firewall --> LAN --> DMZ
internet <--> Firewall <-- LAN | V DMZ which uses a single (3-legged) firewall box and doesn't force traffic from LAN to DMZ to transit the Internet (or vice versa) as the alternatives above do. (The arrowheads, as I've indicated them above, reflect directions of allowed session initiation.) David Gillett --------------------------------------------------------------------------- Evaluating SSL VPNs' Consider NEOTERIS, chosen as leader by top analysts! The Gartner Group just put Neoteris in the top of its Magic Quadrant, while InStat has confirmed Neoteris as the leader in marketshare. Find out why, and see how you can get plug-n-play secure remote access in about an hour, with no client, server changes, or ongoing maintenance. Visit us at: http://www.neoteris.com/promos/sf-6-9.htm ----------------------------------------------------------------------------
Current thread:
- Re: Firewall and DMZ topology, (continued)
- Re: Firewall and DMZ topology Christopher Ingram (Jun 09)
- Re: Firewall and DMZ topology Erik Vincent (Jun 09)
- Re: Firewall and DMZ topology Christopher Ingram (Jun 09)
- Re: Firewall and DMZ topology Erik Vincent (Jun 09)
- Re: Firewall and DMZ topology Brad Mills (Jun 10)
- Re: Firewall and DMZ topology - Thanks for all the information William J. Burgos (Jun 11)
- RE: Firewall and DMZ topology Mann, Bobby (Jun 09)
- RE: Firewall and DMZ topology ed (Jun 10)
- Re: Firewall and DMZ topology Erik Vincent (Jun 10)
- Re: Firewall and DMZ topology Daniel B. Cid (Jun 10)
- RE: Firewall and DMZ topology ed (Jun 10)
- Re: Firewall and DMZ topology Christopher Ingram (Jun 09)
- Re: Firewall and DMZ topology Chris Berry (Jun 10)
- RE: Firewall and DMZ topology David Gillett (Jun 10)
- Re: Firewall and DMZ topology Erik Vincent (Jun 10)
- Re: Firewall and DMZ topology Zach Crowell (Jun 10)
- Re: Firewall and DMZ topology Erik Vincent (Jun 10)
- VPN vs changing routes Keenan Smith (Jun 10)
- Re: VPN vs changing routes chort (Jun 10)
- RE: VPN vs changing routes David Gillett (Jun 10)
- Re: [security] VPN vs changing routes Martin (Jun 11)
- Re: VPN vs changing routes Joerg Over Dexia (Jun 11)
- Re: Firewall and DMZ topology Daniel B. Cid (Jun 10)
- Re: Firewall and DMZ topology Steve Bremer (Jun 10)