mjr @
tis .
com writes:
> >[...]
> >(screened subnet with all internet-internal net traffic blocked)
> >
> >Internet -----[router]-------|-------[router]-----Internal net
> > |
> > [bastion host]
> >
> >
> >
> >(dual-homed gateway wrapped with screening routers)
> >
> >Internet -----[router]----[bastion gateway]----[router]-----Internal net
>
> ^^^^^^^^
> Not Needed
>[...]
> The tradeoff is that you then *never* have the option of
> routing any traffic through. [...]
How does the availability of screend on your "bastion gateway" effect
that statement?
Is it crazy to think about using screend to do some filtering on the
same machine that was running app. gateways?
g.
References:
|
|