Image
 
linkedin_logo.png rss_logo.jpg
twitter_logo.png youtube_logo.jpg
Latest Additions
 
EH-Net Login
Welcome Guest.






Lost Password?
No account yet? Register
Who's Online
We have 36 guests online
 
Advertisement

You are here: Home arrow Ethical Hacking Discussions and Related Certificationsarrow Otherarrow network design question/advice request (hw/sw)
EH-Net
May 25, 2013, 03:13:06 AM *
Welcome, Guest. Please login or register.
Did you miss your activation email?

Login with username, password and session length
News: Go back to The Ethical Hacker Network Online Magazine Home Page
 
   Home   Help Calendar Login Register  
Pages: [1]   Go Down
  Print  
Author Topic: network design question/advice request (hw/sw)  (Read 3249 times)
0 Members and 1 Guest are viewing this topic.
RobertK
Newbie
*
Offline Offline

Posts: 1


View Profile
« on: March 05, 2008, 04:23:00 PM »

Is there any advantage (or perhaps I should ask, *what are the advantages*) of having a separate physical server as a firewall, another for a dmz/internet server, and another as an internal/intranet server?

Big Bad Internet
|
dmz/internet server
--------Firewall--------
wireless router
|
intranet server, other stuff

For the sake of argument, let's say that the following is true:
-firewall is running a linux firewall (astaro, endian, engarde, take your pick), has a quad port ethernet card connecting as above
-the dmz/internet is runnning selinux (engarde)
-the wireless router is untrusted and ip's are tied to known mac addresses
-on the internal side, the intranet server and asterix/trixbox servers are running selinux (engarde), there is the usual bevy of stuff on the internal side (storage area network, users, etc)
-there are (obviously) switches between the firewall and dmz, and between the firewall and the internal stuff

+Is this overcomplex? Should we instead integrate the (untrusted) dmz/internet and (trusted) intranet, asterix, etc onto the firewall?
+what am i missing from a design standpoint?
Logged
BillV
Hero Member
*****
Offline Offline

Posts: 1892


View Profile WWW
« Reply #1 on: March 05, 2008, 06:00:42 PM »

+Is this overcomplex? Should we instead integrate the (untrusted) dmz/internet and (trusted) intranet, asterix, etc onto the firewall?
+what am i missing from a design standpoint?

What are the requirements? You're asking something that is pretty open-ended and not really specific. I would not integrate your other servers onto the firewall. The firewall should only serve 1 purpose, to be a firewall. I wouldn't host anything else on it.

I have pretty much the exact same setup at home. A firewall (EnGarde) with 4 network ports (Internet, Web Server, Wireless Router, Internal). I'm currently not using the web server, and the firewall does not allow traffic between wireless <-> internal. This allows me to open the wireless (if wanted), but is currently protected by MAC filters and WPA2.

Make sure you're filtering both inbound and outbound traffic and you have a pretty solid setup.
Logged
Kev
Sr. Member
****
Offline Offline

Posts: 428


View Profile
« Reply #2 on: March 05, 2008, 11:17:48 PM »

Yes I agree you should not host anything other than a firewall on a single host.  There  have been times I have encountered a box with too many things running on it.  If I could find a weakness and gain access, well everything else fell apart as far as security goes.
Logged
Pages: [1]   Go Up
  Print  
 
Jump to:  

Powered by MySQL Powered by PHP Powered by SMF 1.1.18 | SMF © 2013, Simple Machines
Joomla Bridge by JoomlaHacks.com
Valid XHTML 1.0! Valid CSS!
Page created in 0.073 seconds with 23 queries.
 
Exclusive Deal

sansfire13_245x90_cw90.jpg
SANSFIRE 2013
June 15 - 22

5% Off w/ Code: EHN_5

SANS Deals 4 EH-Netters
5% OFF Any SANS Course in Any Format!
Coupon Code: EHN_5 Including SANS Rocky Mountain 2013 & SANS Boston 2013
Polls
Compared to this year, 2013 will be:
 
Recent Forum Topics
EH-Net News Feeds
Latest Additions
 
         
Advertisement

© 2013 The Ethical Hacker Network
Joomla! is Free Software released under the GNU/GPL License.