Great Circle Associates Firewalls
(May 1997)
 

Indexed By Date: [Previous] [Next] Indexed By Thread: [Previous] [Next]

Subject: Re: Firewall architectures
From: "Douglas M. MacFarlane" <madmac @ mcs . net>
Date: Mon, 19 May 1997 12:29:55 -0500 (CDT)
To: Frederick M Avolio <avolio @ tis . com>
Cc: Domenico Viggiani <dviggian @ gst . cgs . it>, firewalls @ GreatCircle . COM
In-reply-to: <3 . 0 . 1 . 32 . 19970519090426 . 00702470 @ pop . hq . tis . com>

In addition to the "DMZ inside or outside the proxy server" issue,
the 2nd options doesn't show a router at the backend of the complex.
Hence, there are no filtering rules protecting your firewall
(proxy/bastion) from internal attack.  This is, in my humbe opinion,
a cardinal error.

Doug


On Mon, 19 May 1997, Frederick M Avolio wrote:

> The obvious is that the firewall in the second case protects the DMZ. This
> is a good thing from a security standpoint. Some prefer the first, trading
> off security for speed. The extra security benefit in the second diagram
> mkes it worth it to test both set-ups to see if there really is any
> performance hit for #2.
> 
> f
> 
> At 02:02 PM 5/19/97 +0200, Domenico Viggiani wrote:
> >I'm sorry for the obvious question (peraphs it is a FAQ).
> >What are the differences between this architecture:
> >
> >Internet ----- Router ----- Firewall ----- DMZ ----- Router -----
> >Internal Network
> >
> >and this one:
> >
> >Internet ---- Router ----- DMZ ----- Firewall ----Internal Network
> >
> >I found both of them in two real-world sites but I don't understand well
> >their pro and cons.
> >
> >Thank you in advance.
> >Mimmo
> >-- 
> >
> >Domenico Viggiani                Internet Systems Engineer
> >CAP GEMINI ITALY SpA	       E-mail: dviggian @
 gst .
 cgs .
 it
> >Via dei Berio, 91 - 00155 Roma      Phone: +39 6 23190 509
> >
> >
> 

Douglas M. MacFarlane
Principal, Vauban Industries
madmac @
 mcs .
 net



References:
Indexed By Date Previous: Mib definition
From: mgarcia @ accesosis . es (Manuel Garcia - Acceso Sistemas -)
Next: Solstice F-1 for NT. Is this possible?
From: Fernando Cabral <fcabral @ ibase . br>
Indexed By Thread Previous: Re: Firewall architectures
From: Frederick M Avolio <avolio @ tis . com>
Next: Re: Firewall architectures
From: Adam Shostack <adam @ homeport . org>

Google
 
Search Internet Search www.greatcircle.com