Nmap Security Scanner
*Intro
*Ref Guide
*Install Guide
*Download
*Changelog
*Book
*Docs
Security Lists
*Nmap Hackers
*Nmap Dev
*Bugtraq
*Full Disclosure
*Pen Test
*Basics
*More
Security Tools
*Pass crackers
*Sniffers
*Vuln Scanners
*Web scanners
*Wireless
*Exploitation
*Packet crafters
*More
Site News
Site Search:
Exploit World
Advertising
About/Contact
Credits
Sponsors:




basics logo Security Basics mailing list archives

Re: What is more secure?
From: Chris Thorp <thorp () spacia org>
Date: Mon, 28 Feb 2005 08:10:53 -0700


if he [a cracker] succeed he will gain all access to both networks:
Tomas,

I assume from this statement that you are using one triple homed firewall? If so, I'd suggest using two dual homed firewalls which are running different OSes with all publicly routable IPs.assigned to the outer firewall. That way if the outer firewall is broken, the attacker will only have access to the DMZ (assuming the internal firewall is configured such that the same attack won't work on both).

My 2 cents,
-Chris


  By Date           By Thread  

Current thread:
[ Nmap | Sec Tools | Mailing Lists | Site News | About/Contact | Advertising | Privacy ]