Add a separate internal firewall for the remote users. Enable strong
authentication on the RAS box. Have the internal servers protected
via a series of guards related to the individual internal policies.
Craig
> >
> >Where should a RAS-Server be placed ?
> >
> ...
> >The internal net is protocted by a firewall with three nics Internet,
> >internal net, DMZ).
> >Now I am not shure if it make sense to put the RAS-Server into the
> DMZ.
> >Do I get additional security or am I opening a gap?
>
>
---------------------------------------------------
Craig S. Wright
Network Security Specialist
Australian Stock Exchange
___________________________________________________
|
|