Great Circle Associates Firewalls
(July 1997)
 

Indexed By Date: [Previous] [Next] Indexed By Thread: [Previous] [Next]

Subject: Re: router on external net
From: ping <ping @ tm . net . my>
Organization: The Network Connections
Date: Mon, 07 Jul 1997 23:44:29 -0700
To: Chris Pressley <chrisp @ tidalwave . net>
Cc: firewalls-digest @ GreatCircle . COM
References: <3 . 0 . 1 . 32 . 19970703120351 . 006bf660 @ postoffice . tidalwave . net>
Reply-to: ping @ tm . net . my

Chris Pressley wrote:
> 
> Assume I setup a dual-homed firewall. My internal net connects to the
> internal interface on the firewall, and my external interface on the
> firewall connects to a T-1, then on to the ISP's router. The interface on
> my ISP's router is on the same network as my external interface. Two
> questions:
> 
> 1. Do I need a router between my firewall external interface and my T-1 (I
> have to connect something to the CSU/DSU, right?).

If you can convert signal from your CSU/DSU to whatever interface at
your
firewall, then you don't need it coz the firewall machine can run
routed.

> 
> 2. Should I have a router between my firewall external interface and my
> T-1, give that my ISP's router is on the same network, for security reasons?

I would recommend a router, beside routing it should do some simple 
packet filtering before hitting the firewall.

> 
> Thanks,
> Chris

-- 
--------------------------------------------------------------
Ping Onn Cheng                 The Network Connections
Network Consultant             41 Jalan USJ 10/1, Taipan Crest
Tel : 03-7337757               Subang Jaya, Selangor
http://www.asiapac.net/~ping   Malaysia
--------------------------------------------------------------


References:
Indexed By Date Previous: Re: Two ISP's to one DMZ
From: marc @ sniff . ct-net . de
Next: FW1 example URI specification file needed
From: "Crawford, Jim E." <Jim . Crawford @ Centrilift . com>
Indexed By Thread Previous: router on external net
From: Chris Pressley <chrisp @ tidalwave . net>
Next: RE: router on external net
From: "Stackpole, Bill" <BSTACKPO @ sla . com>

Google
 
Search Internet Search www.greatcircle.com