Firewall Wizards mailing list archives

Re: Reverse Proxy on DMZ


From: "Perry E. Metzger" <perry () piermont com>
Date: 11 Jan 1999 12:50:36 -0500


Joel Snider <joel_snider () yahoo com> writes:
I am sure that this has been discussed here before, but was unable to
find any references in the archives.  What are the pros and cons of
using a proxy (caching) server on a DMZ segment to allow access to an
internal web server?  The DMZ is hanging off a segment on a firewall.
The server would be used to provide extranet applications. Any
comments would be greatly appreciated. Thanks...

One questions what the point of having a firewall is if you are
providing access to web based applications running inside your
site. A web server is almost without a doubt the easiest thing to
break in to, so providing external access to a web server running on
the inside sort of obviates the whole point of having a firewall in
the first place.

.pm



Current thread: