Great Circle Associates Firewalls
(December 1996)
 

Indexed By Date: [Previous] [Next] Indexed By Thread: [Previous] [Next]

Subject: Re: Dual-porting of DMZ systems, why?
From: Frank Willoughby <frankw @ in . net>
Date: Sat, 21 Dec 96 21:11:37 -0500
To: Michael Smith <ms @ gf . org>
Cc: firewalls @ GreatCircle . com

At 02:08 PM 12/19/96 -0500, Michael Smith <ms @
 gf .
 org> allegedly wrote:

>I'm wondering just what class of attack scenarios is 
>thought to be prevented by dual-porting the DMZ 
>systems, thus: 
>
>             |---DMZ sys---|
>             |             |
>             |             |
>             |             |
>outer        |             |    inner
>boundary-----|---DMZ sys---|----boundary
>router       |             |    router
>             |             |
>             |             |
>             |---DMZ sys---|
>
>
>As opposed to:
>
>             |---DMZ sys
>             |             
>             |             
>             |---DMZ sys             
>outer        |                 inner
>boundary-----|-----------------boundary
>router       |                 router
>             |                        
>             |---DMZ sys
>
>
>The only thing I can think of that the first one gives you 
>and the second one doesn't, is protection against some subversion
>of the outer boundary router. Are there other benefits that 
>I've overlooked? 
>
>  
>
>--Michael Smith
>  ms @
 gf .
 org
>

The thing that jumps to mind first is that you need a firewall.  
While some may consider a router to be a "firewall", I don't as
it does not provide adequate protection from the hazards of the
Internet.  You might try using an Application Gateway which 
supports User->Firewall Encryption.

Best Regards,


Frank
Fortified Networks Inc.	
Expert Information Security Consulting
Phone: (317) 573-0800  Fax: (317) 573-0817) 
http://www.fortified.com


Indexed By Date Previous: Re: Firewall checklist
From: Frank Willoughby <frankw @ in . net>
Next: Re: Wierd [ cisco revers telnet ports 200x ]
From: Rafi Sadowsky <rafi @ tavor . openu . ac . il>
Indexed By Thread Previous: Dual-porting of DMZ systems, why?
From: Michael Smith <ms @ gf . org>
Next: NT vs. UNIX Firewall positioning
From: "Stout, Bill" <bill . stout @ hidata . com>

Google
 
Search Internet Search www.greatcircle.com