Re: dmz access out



On Apr 28, 9:28 pm, "flamer die.s...@xxxxxxxxxxx"
<die.s...@xxxxxxxxxxx> wrote:
are the hosts on the dmz on the same subnet as the protected hosts on
the lan? you definately want to use a different subnet off a different
router interface, if a machine on your dmz becomes comprised (which is
why its on a dmz to begin with) then the attacker can access the
machines on your LAN from the machine on the dmz (within the same
broadcast domain).

Have a look athttp://www.parkansky.com/tutorials/dmz.htmfor a basic
example.

Flamer.

This is on an asa5510 firewall. So yes it is a different subnet on a
seperate interface. So - if i give it the access list above then i'm
thinking that i will still be protected from traffic originating from
the outside. But that all traffic originating from the inside will
still be able to go through. Does this hold true for the asa. Thanks
.



Relevant Pages

  • Re: dmz access out
    ... you definately want to use a different subnet off a different ... router interface, if a machine on your dmz becomes comprised (which is ... machines on your LAN from the machine on the dmz (within the same ...
    (comp.dcom.sys.cisco)
  • Re: modify the SRV weightings
    ... Although if you did this you would have to change the IP subnet of the DMZ ... value to 0 no clients will use it for authentication. ... >> Now I want that the clients only connect to the ad from the dc in my lan. ...
    (microsoft.public.windows.server.active_directory)
  • Re: dmz access out
    ... are the hosts on the dmz on the same subnet as the protected hosts on ... if a machine on your dmz becomes comprised (which is ... machines on your LAN from the machine on the dmz (within the same ...
    (comp.dcom.sys.cisco)
  • Re: Firewall and DMZ topology
    ... attacker cannot spread his influence across the network. ... If the DMZ resides between the public Internet and the ... Should the DMZ be behind the LAN and not split off at the firewall, ... > The Gartner Group just put Neoteris in the top of its Magic Quadrant, ...
    (Security-Basics)
  • Re: Web portal security
    ... win2003 standard server with IIS, SSL enabled and will be placed on ... So I will be fwding port 443 in firewall to my DMZ port. ... Well, assuming you are going to use teh SQL database from SBS, you can ... subnet than my LAN and map one to one from firewall to dmz. ...
    (microsoft.public.windows.server.sbs)