Firewall Wizards mailing list archives
Re: DMZ Ideas
From: Kevin <KKadow () gmail com>
Date: Thu, 30 Sep 2004 22:14:17 -0500
On Thu, 30 Sep 2004 15:58:41 -0400, Mark F. <firewalladmin () bellsouth net> wrote:
My question is this - What would make a good DMZ for this setup? We have a few suggestions up in the air and it's all prliminary stuff
right now. Some ideas are VLAN's (in my opinion too much management overhead, room for error and not necessarily very secure), seperate subnet on router, etc. . . .
The site is the size of a big college campus, so separating the devices onto a seperate backbone/subnet will be physically difficult and expensive as well.
I have never trusted VLANs as a security measure, but I understand the cost issues involved in separating the devices onto a separate backbone. I'm assuming that you cannot add security to the readers (wireless client devices), but are not all that concerned about the devices sending bad data to the application, but rather about an intruder taking the MAC of an authorized device and getting on the internal network? One approach to provide improved security over simple VLANs is to use fiber to connect a group of physically proximate access points to a switch, and then use GRE tunnels (on the switch or in a dedicated device) to transport the traffic across your LAN or WAN to where the firewall is located. If you are really paranoid, you can do the following: [WAP]=[Cisco 25xx router]-[Filter rtr]---WAN---[Filter rtr]-[Router 2]=[Firewall] Where the WAP is Ethernet connected to a 25xx router which encapsulates the IP traffic in GRE, and the uplink from the encapsulating router is passed into a "trusted' network router on a filtered interface which will only pass GRE packets destined for "Router 2". Router 2 is the other end of the GRE tunnel, and could have a filtered interface between it and the WAN router. The point is that even if you get on the wireless network and take over the next hop router, you can't get into the LAN/WAN, you can only stuff GRE packets down the pipe towards the firewall. _______________________________________________ firewall-wizards mailing list firewall-wizards () honor icsalabs com http://honor.icsalabs.com/mailman/listinfo/firewall-wizards
Current thread:
- RE: DMZ Ideas Luke Butcher (Sep 30)
- <Possible follow-ups>
- Re: DMZ Ideas Marcus J. Ranum (Sep 30)
- Re: DMZ Ideas Kevin (Oct 01)
- Re: DMZ Ideas Carric Dooley (Oct 01)
- Re: DMZ Ideas Dale W. Carder (Oct 05)
