Firewall Wizards mailing list archives
Re: Placement of a VPN Appliance
From: Jeffery.Gieser () minnesotamutual com
Date: Thu, 4 Jan 2001 09:02:54 -0600
We recently had the same issue where I work. I decided to place the public side of the VPN device on a dmz and the private side on our internal network. This was done for the following reasons. 1. If every device has X number of vulnerabilities then having two devices of different types on the internet gives us X + X number of different vulnerabilities. 2. The firewall really can't do much filtering for the VPN device for ISAKMP, AH, or ESP but it can stop any other traffic from reaching the VPN device that isn't one of these three protcols. 3. I would place the public side of the VPN on the DMZ because I wouldn't want potentially dirty traffic on my internal network befire it reached it's checkpoint. 4. Placing the private side of the VPN device in front of a firewall defeats the purpose of a firewall since you usually want the people on the other side of the VPN to have full access to your internal network. My firewall rules would look like swiss cheese if I did that. Regards, Jeffery Gieser _______________________________________________ firewall-wizards mailing list firewall-wizards () nfr com http://www.nfr.com/mailman/listinfo/firewall-wizards
Current thread:
- Placement of a VPN Appliance Crist Clark (Jan 03)
- <Possible follow-ups>
- RE: Placement of a VPN Appliance Ben Nagy (Jan 03)
- Re: Placement of a VPN Appliance Crist Clark (Jan 03)
- Re: Placement of a VPN Appliance Jeffery . Gieser (Jan 04)
- Re: Placement of a VPN Appliance Bill_Royds (Jan 04)
- RE: Placement of a VPN Appliance Stewart, John (Jan 04)
- RE: Placement of a VPN Appliance Bob . Eichler (Jan 04)
- RE: Placement of a VPN Appliance Jeffery . Gieser (Jan 04)
- RE: Placement of a VPN Appliance Ben Nagy (Jan 04)
- RE: Placement of a VPN Appliance Ben Nagy (Jan 04)
- Re: Placement of a VPN Appliance dharris (Jan 04)
- Re: Placement of a VPN Appliance R. DuFresne (Jan 05)
- Re: Placement of a VPN Appliance JB (Jan 08)
- Re: Placement of a VPN Appliance R. DuFresne (Jan 05)
- RE: Placement of a VPN Appliance David Bovee (Jan 05)
(Thread continues...)