Ethical Hacking Learn to find vulnerabilities before the bad guys do! Gain real world hands on hacking experience in our state of the art hacking lab. Course designed and taught by expert instructors with years of penetration testing experience. 12 student maximum in every class. Certification attempt included in every package. | Computer Forensics Training at InfoSec Institute Gain the in-demand skills of a certified computer examiner, learn to recover trace data left behind by fraud, theft, and cybercrime perpetrators. Discover the source of computer crime and abuse at your organization so that it never happens again. All of our class sizes are guaranteed to be 12 students or less to facilitate one-on-one interaction with one of our expert instructors. |

| Subject: | Re: Firewall positioning in Large Network |
|---|---|
| Date: | Wed, 27 Jun 2007 10:41:19 -0700 |
Mubin,
This is a tough question to answer without a better understanding of
your network and the various services running on it. It also comes down to
a security methodology of do you want physical or logical separation. For
example I prefer to have the perimeter devices as physically separate as
possible. I have seen people connect their boarder router, F/W, and dmz
severs all onto the same core switch. This just scares me. I typically
like the boarder router and fw on one smaller switch and dmz on a second,
then core on a 3rd. Not all environments can due this.
you may want to take a look at our website http://www.redseal.net I
would be happy to hook you up with a demo of our software, I would even do a
webex once you have it up and running to help you with this question. Let
me know if your interested.
Cheers,
Brian
--------------------------------------------------------------------
Brian Laing
Chief Security Officer
Cellphone: +1 650.280.2389
Office: +1 (888) 845-8169 Ext. 805
Email: brian@redseal.net
Redseal Systems http://www.redseal.net
Instant Visibility. Threats Averted.
-------------------------------------------------------------------
From: Mubin Shaikh <mubines@yahoo.com>
Date: Wed, 20 Jun 2007 04:34:04 -0700 (PDT)
To: <security-basics@securityfocus.com>
Subject: Firewall positioning in Large Network
Resent-From: <security-basics-return-44888@securityfocus.com>
Resent-Date: Wed, 20 Jun 2007 11:28:53 -0600 (MDT)
Hi,
Question -
What is the best logical placement for firewall in
large network?
If I have 3000+ user organisation with both core and
access switch available, will i connect my firewall to
core switch or access switch ? and why ?
Thanks
-Mubin
____________________________________________________________________________
________
Fussy? Opinionated? Impossible to please? Perfect. Join Yahoo!'s user panel
and lay it on us.
http://surveylink.yahoo.com/gmrs/yahoo_panel_invite.asp?a=7
| <Prev in Thread] | Current Thread | [Next in Thread> |
|---|---|---|
| ||
| Previous by Date: | Open Source Router with NAT, Mohamed Farid |
|---|---|
| Next by Date: | Re: need suggestion - pen-test tools, phillip@cryptolife.org |
| Previous by Thread: | RE: Firewall positioning in Large Network, Hesham Sabry |
| Next by Thread: | Re: Re: Firewall positioning in Large Network, evilwon12 |
| Indexes: | [Date] [Thread] [Top] [All Lists] |