Ethical Hacking

Learn to find vulnerabilities before the bad guys do! Gain real world hands on hacking experience in our state of the art hacking lab. Course designed and taught by expert instructors with years of penetration testing experience. 12 student maximum in every class. Certification attempt included in every package.
Computer Forensics Training at InfoSec Institute

Gain the in-demand skills of a certified computer examiner, learn to recover trace data left behind by fraud, theft, and cybercrime perpetrators. Discover the source of computer crime and abuse at your organization so that it never happens again. All of our class sizes are guaranteed to be 12 students or less to facilitate one-on-one interaction with one of our expert instructors.




Network Security Firewalls
[Top] [All Lists]

Re: Host placement and DMZ internal/external questions.

Subject: Re: Host placement and DMZ internal/external questions.
Date: Wed, 19 Oct 2005 18:18:48 +0200
Hello Adam,

Well, let me try to help you by explaining you my point of view :
 to 1 :
 A host which has access to internal network, should not be placed in
 the DMZ, what should be the purpose of having a DMZ then ?
 Immagine, you will have to configure the (inner) router to allow
 inbound trafic from that host, so if it is getting compromissed, you
 allow an attacker full access to internal network, and all he has to
 do is to enter the DMZ.
 to 2:
 Mail server could be in there, if you configure that one properly you
 can runt it on the bastion host.
 Antivirus server ... no way ... antivirus update server... no way.
 Immagine that someone would be able to compromit that machine, and
 replace your antivirus updates with malicious code, or change
 components of antivirus software itself, that coudl compromit your
 whole internal network.

 Just my 2 cents. Enjoy.


 regards,
 Adam Pal

Wednesday, October 12, 2005, 1:10:08 PM, you wrote:

<==============Original message text===============
AT> I have a few questions I have about dmz internal and external networks
AT> that I need help with.

AT> 1 if you have a host such as citrix that must have access to the
AT> internal network does that sit on your DMZ?

AT> 2 antivirus mail gateway servers / Antivirus update server does that
AT> sit on your DMZ ?

AT> 3 a squid proxy that internal hosts access

AT> with the examples above do I place the hosts on the DMZ and then
AT> modify firewall rules so that the host has the access they need to
AT> perform as an internal network host? if so how is that different than
AT> opening up a specific port directed to a specific host on internal
AT> network for outside world access?

AT> part of my confusion lies in that when I think DMZ I think that the
AT> host should never touch the internal network and be left out in the
AT> DMZ alone.

AT> I hope I have stated my questions clearly
AT> thank you for your responses.

AT> /at

<===========End of original message text===========



-- 
Best regards,
 Adam Pal                            mailto:pal_adam@gmx.net

<Prev in Thread] Current Thread [Next in Thread>