>
> Any opinions on this?
>
But of course. ,-)
>
>
> Normal:
> Bastion Host
> |
> Internet -----> Screening Router -------|
> |
> Inside Network
>
>
>
> Modified:
>
>
> Bastion Host
> |
> Internet -----|-----> Screening Router ----> Inside Network
>
Actually, if you have the hardware, you may want to consider:
|
internet -----+------> bastion host -------+------+ local ethernet
| a | |
screening screening
router router
a b
This way, "bastion host a" can be the sole occupant for a particular
network, what we call a perimeter network. This box can not only act
as a "bastion," as folks like to call them, but it can also house all
proxy services and act as an application gateway, if necessary.
This box can also be the only IP network advertised to the remainder
of the Internet community in the policy routing database.
Just a spin on things.
Cheers,
_______________________________________________________________________________
Paul Ferguson
US Sprint
Managed Network Engineering tel: 703.904.2437
Herndon, Virginia USA internet: paul @
hawk .
sprintmrn .
com
References:
|
|