Great Circle Associates Firewalls
(February 1996)
 

Indexed By Date: [Previous] [Next] Indexed By Thread: [Previous] [Next]

Subject: Re: How secure can a screened host be?
From: Bill Stout <bstout @ osc . hitachi . com>
Date: Fri, 2 Feb 96 08:36:12 PST
To: sgcccdc @ citec . qld . gov . au (Colin Campbell)
Cc: Firewalls @ GreatCircle . COM

>> I have a theoretical configuration where I would like to use a screened
>> host, AND Cisco policy routing.  The bennies would be the ability to
>> firewall multiple links with one router.  My concern is the overall security
>> of such an arrangement in comparison to a true DMZ.
>> 
>> <diagram follows>
>> 
>>          Business partner---Router----Internal Net(s)
>>                             /  | \
>>                  Internet--/   |  \---Firewall
>>                                |
>>                           Web Server(s)
>> 
>
>My problem with this is that your firewall/bastion is neither logically
>nor physically between the internet router and the internal net(s).
>...
>Colin

Same initial thoughts here.  'By the book Firewall design' logic would state 
there are obvious design flaws here.  But the books were written before Cisco
introduced 'policy routing', where all traffic from specific ports are sent 
to a specific IP address, which would be the firewall.  The logical layout 
would then be:

        Business partner
                        \
                        Firewall----Internal networks
                        /      \   
                Internet        Web Servers

Any additional segments can be directed to the Firewall also.

BTW - This is a sanity check, I want to find errors with this configuration.

William B. Stout
Senior Systems Administrator
Hitachi Data Systems
Open Systems Center
Santa Clara, California


Indexed By Date Previous: Re: Internet-access from Nov
From: "Dan Vukelich" <Dan_Vukelich @ qmgateib . mitre . org>
Next: Re: NIS+
From: "Mikolaj J. Habryn" <dichro @ tartarus . uwa . edu . au>
Indexed By Thread Previous: Re: Internet-access from Nov
From: "Dan Vukelich" <Dan_Vukelich @ qmgateib . mitre . org>
Next: NFS services and firewalls
From: igood @ mprgate . mpr . ca (Ian Good)

Google
 
Search Internet Search www.greatcircle.com