Fast DMZ backups



Hi all,

I'm looking at bringing a backup server from the DMZ into the LAN. I
need something to put between the DMZ clients and the server to protect
it while giving me the best throughput possible. I'd be happy with
extended access-lists, and so have been looking at an L3 switch.

Is it possible to configure extended access-lists that would allow the
backup server to communicate with the clients in the DMZ, which
protecting the internal network in case the backup server is
compromised? I am still exploring whether the client attempts to
initiate a session on a random port (a la ftp) or whether its a pure
pull.

What are my alternatives?

Ta

.



Relevant Pages

  • Re: Fast DMZ backups
    ... :I'm looking at bringing a backup server from the DMZ into the LAN. ... :need something to put between the DMZ clients and the server to protect ...
    (comp.dcom.sys.cisco)
  • Re: Access denied on network share in an other domain
    ... Are the clients transferring files straight into the live service on the DMZ; or are they transferring them to you to do something with? ... I don't see any reason for your internal network to trust the DMZ ...
    (microsoft.public.windows.server.security)
  • Re: frontend/backend question
    ... I have this exact configuration....your outlook clients on ... I have a frontEnd server ... in its own dmz for my owa users and it also routes all ...
    (microsoft.public.exchange.admin)
  • Re: Access denied on network share in an other domain
    ... My clients will transfer live on the DMZ. ... My programmers will access them through FTP. ... files back in the Internal network by either FTP or HTTPS. ...
    (microsoft.public.windows.server.security)
  • Re: DMZ backup strategies
    ... > What sort of methods are most people using to backup servers on a DMZ? ... > most cost effective solution would employ an internal backup server to hit ... cd-rom along with a copy of the Ghost executable for quick rebuilds. ...
    (comp.security.firewalls)