Re: Fast DMZ backups
- From: roberson@xxxxxxxxxxxxxxxxxx (Walter Roberson)
- Date: Wed, 3 Aug 2005 19:41:34 +0000 (UTC)
In article <1123053307.142923.52660@xxxxxxxxxxxxxxxxxxxxxxxxxxxx>,
<yamahasw40@xxxxxxxxxxxxx> wrote:
:I'm looking at bringing a backup server from the DMZ into the LAN. I
:need something to put between the DMZ clients and the server to protect
:it while giving me the best throughput possible. I'd be happy with
:extended access-lists, and so have been looking at an L3 switch.
:Is it possible to configure extended access-lists that would allow the
:backup server to communicate with the clients in the DMZ, which
:protecting the internal network in case the backup server is
:compromised?
Not really, but 'reflexive' access-lists come much much closer.
:I am still exploring whether the client attempts to
:initiate a session on a random port (a la ftp) or whether its a pure
:pull.
What throughput do you need? "best possible" could get pretty expensive
by the time you get into the petabit per second range.
:What are my alternatives?
PIX 506E and up are rated at 100 Mbit/s cleartext or better.
The x8xx routers have line-rate packet inspection, but the 'line'
is only small multiples of T1 speed in the lower end of the line.
There is a new line of security appliances that I haven't had a look at.
The 3600 series -above- the 3640 can handle 100 Mbit/s; if your traffic
occurs in long streams, then there might not be much traffic inspection
needed, so any slowdowns from CBAC might not be of importance.
The Cat 3560 and Cat 3750 multilayer switch can do gigabit on multiple
ports, but I don't recall that they support reflexive ACLs, just
extended ACLs. They weren't designed as security devices per se.
--
'The short version of what Walter said is "You have asked a question
which has no useful answer, please reconsider the nature of the
problem you wish to solve".' -- Tony Mantler
.
- References:
- Fast DMZ backups
- From: yamahasw40
- Fast DMZ backups
- Prev by Date: Cisco IOS 12.4 =<> 3000 VPN concentrator?
- Next by Date: Re: icmp type 11 cause pix to deny traffic
- Previous by thread: Fast DMZ backups
- Next by thread: Cisco Call manager express & IAX ? with IAX help please
- Index(es):
Relevant Pages
|