Great Circle Associates Firewalls
(July 1997)
 

Indexed By Date: [Previous] [Next] Indexed By Thread: [Previous] [Next]

Subject: Re: Two ISP's to one DMZ
From: Steven Gordiany <sgordiany @ verisign . com>
Date: Sun, 06 Jul 1997 20:44:30 -0700
To: Bertrum Carroll <bc17684 @ 90 . deere . com>, "Firewalls @ GreatCircle . COM" <Firewalls @ GreatCircle . COM>

At 08:36 AM 7/6/97 -0500, Bertrum Carroll wrote:
>I'm looking for advice from someone who has connected two or more
>different ISP's to the same DMZ.
>
>Are there pitfalls in doing this?  Is it not possible.  I need to stay
>up to aleast part of the net when a single ISP is having problems.

You will have to configure your outbound routers to run Border
Gateway protocol (BGP) routing in this case.

The only pitfall is configuring BGP to suit you particular
environment. Border Gateway Protocol can be somewhat complicated if
you've never configured it before. The other issue is dealing with both
ISP's; sometimes they don't want to route each others address blocks.

Redundancy is the issue here, if your running BGP and one of your ISP's
has trouble, BGP will automatically (if configured right) announce an 
alternate route to your DMZ addresses through the 2nd ISP. Convergence
time using the 2nd route is minimal, it should take 5 minutes or so.
>
>Has anyone done this with success?
>
>
Yes.


Follow-Ups:
Indexed By Date Previous: Cisco exploits/vulnerabilities
From: "Gasparini, Edy" <GASPARIE @ anz . com>
Next: Re: Two ISP's to one DMZ
From: marc @ sniff . ct-net . de
Indexed By Thread Previous: Re: Two ISP's to one DMZ
From: Mark Teicher <mht @ clark . net>
Next: Re: Two ISP's to one DMZ
From: marc @ sniff . ct-net . de

Google
 
Search Internet Search www.greatcircle.com