Great Circle Associates Firewalls
(April 1996)
 

Indexed By Date: [Previous] [Next] Indexed By Thread: [Previous] [Next]

Subject: Re: Structure
From: Adam Safier <asafier @ explorer . csc . com>
Date: Wed, 10 Apr 96 16:16 EDT
To: "Ward, Jay" <wardj @ hq . hhmi . org>
Cc: Firewalls <firewalls @ GreatCircle . COM>, "Ward, Jay" <wardj @ hq . hhmi . org>

At 10:26 AM 4/9/96 EDT, Ward, Jay wrote:

>>From what I have been told in the past is that I could run into problems 
>putting the httpd server behind the firewall. Is this true? 

Yes.  If the http server is compromised from the outside so is you internal
network.  If the http server serves the outside world put it on the outside
of the firewall.  Better yet, get a third ethernet interface and create a
second firewalled area for your http and DMZ traffic.

 Inet -----F-1 ---- Internal net
            |
            |
           DMZ for www servers, dial up concentrators, etc.

Why isn't your firewall vendor/distriburtor helping you with these design
issues?    Did they take your money, leave the box and walk?

How is Checkpoint on support?



Adam Safier
CSC-SED-Infosec
asafier @
 csc .
 com

"If you show me yours, I still won't show you mine."

Expressed opinions are my own and might not be shared by my employer or
anyone else.


Indexed By Date Previous: Re: Cross Realm Kerberos/DCE Proxy, NAT, UDP
From: Adam Safier <asafier @ explorer . csc . com>
Next: security auditing class
From: Dan <zen @ flying . fish . com>
Indexed By Thread Previous: Structure
From: "Ward, Jay" <wardj @ hq . hhmi . org>
Next: WWW proxy to cut off Java.
From: Yossi Goltz <yossi @ sunserver . ddddf . com>

Google
 
Search Internet Search www.greatcircle.com