Security Basics mailing list archives
RE: External Network / Firewall Setup.
From: lists () ninjafriendly com
Date: Wed, 07 Sep 2005 15:00:48 +0100
Quoting Tim.BUTTON () Dest gov au:
sorry, wrong terminology. I meant if firewall (1) is compromised, firewall (2)but I'm wary of a single point of failure<<<<I'm not sure what you're referring to about a single point of failure.
should prevent attack from getting into the internal network.
avoid that, you'll need multiple devices in HA, which may well be overkill for what you need.
yup, which is just as well because we can't afford it.
Something I'm still unsure about is internal clients connecting tothe mailserver in the DMZ - how much of a security issue is this? Should I use the DMZ mailserver simply as a relay for an internal mailserver?<<< IMHO, better to use your box in the DMZ as a relay only. You can run postfix/sendmail/whatever and use it to do some granular filtering. If you're keen enough, install some different virus scanner/anti-spam software on there, and get your box to pass the mail to that before allowing anything inbound. The other advantage of doing this is that it allows you to kill anything you don't want at the border. Finally, it means that if your internal server blows up or something, you'll still queue inbound mail....which is good. If you get super keen, you can set it up to run iptables and tcpwrappers and tie it down.
Cheers - I have some reading to do.
Current thread:
- External Network / Firewall Setup. lists (Sep 06)
- Re: External Network / Firewall Setup. Michael Gale (Sep 07)
- Re: External Network / Firewall Setup. Ivan . (Sep 07)
- Re: External Network / Firewall Setup. lists (Sep 07)
- RE: External Network / Firewall Setup. Mikhail Minyailov (Sep 07)
- Re: External Network / Firewall Setup. Greg Stiavetti (Sep 07)
- Red Cross needs network security tech volunteers Kelley Greenman (Sep 12)
- Re: External Network / Firewall Setup. Greg Stiavetti (Sep 07)
- RE: External Network / Firewall Setup. David Gillett (Sep 07)
- Re: External Network / Firewall Setup. Jayson Anderson (Sep 08)
- <Possible follow-ups>
- RE: External Network / Firewall Setup. Tim.BUTTON (Sep 07)
- RE: External Network / Firewall Setup. lists (Sep 07)
- Re: External Network / Firewall Setup. Florian Rommel (Sep 07)
- RE: External Network / Firewall Setup. Tim.BUTTON (Sep 07)
- RE: External Network / Firewall Setup. Jayson Anderson (Sep 08)
- RE: External Network / Firewall Setup. Yvonne McInally (Sep 08)