Firewall Wizards mailing list archives

Re: DMZ Ideas


From: Kevin <KKadow () gmail com>
Date: Thu, 30 Sep 2004 22:14:17 -0500

On Thu, 30 Sep 2004 15:58:41 -0400, Mark F. <firewalladmin () bellsouth net> wrote:
My question is this - What would make a good DMZ for this setup?
We have a few suggestions up in the air and it's all prliminary stuff
right now. Some ideas are VLAN's (in my opinion too much management
overhead, room for error and not necessarily very secure), seperate
subnet on router, etc.
. . .
The site is the size of a big college campus, so separating the devices onto a seperate backbone/subnet will be 
physically difficult and expensive as well.

I have never trusted VLANs as a security measure, but I understand the
cost issues involved in separating the devices onto a separate
backbone.  I'm assuming that you cannot add security to the readers
(wireless client devices), but are not all that concerned about the
devices sending bad data to the application, but rather about an
intruder taking the MAC of an authorized device and getting on the
internal network?


One approach to provide improved security over simple VLANs is to use
fiber to connect a group of physically proximate access points to a
switch, and then use GRE tunnels (on the switch or in a dedicated
device) to transport the traffic across your LAN or WAN to where the
firewall is located.

If you are really paranoid, you can do the following:

[WAP]=[Cisco 25xx router]-[Filter rtr]---WAN---[Filter rtr]-[Router
2]=[Firewall]

Where the WAP is Ethernet connected to a 25xx router which
encapsulates the IP traffic in GRE, and the uplink from the
encapsulating router is passed into a "trusted' network router on a
filtered interface which will only pass GRE packets destined for
"Router 2".

Router 2 is the other end of the GRE tunnel, and could have a filtered
interface between it and the WAN router.

The point is that even if you get on the wireless network and take
over the next hop router, you can't get into the LAN/WAN, you can only
stuff GRE packets down the pipe towards the firewall.
_______________________________________________
firewall-wizards mailing list
firewall-wizards () honor icsalabs com
http://honor.icsalabs.com/mailman/listinfo/firewall-wizards


Current thread: