networking-forum.com
Community BlogCommunity Wiki * Register  * Search  * Login
View unanswered postsView active topics

All times are UTC - 6 hours [ DST ]



Post new topic Reply to topic  [ 12 posts ] 
Author Message
PostPosted: Mon Jul 25, 2005 6:20 am 
Offline
New Member
New Member

Joined: Mon Jul 25, 2005 6:18 am
Posts: 6
I am looking for resources on how to set up a DMZ without the use of a hardware firewall. I am mostly in need on the necessary access lists for the internal and external routers. Many thanks in advance.


Top
 Profile  
 
 Post subject:
PostPosted: Mon Jul 25, 2005 6:48 am 
Offline
New Member
New Member

Joined: Mon Mar 21, 2005 2:49 pm
Posts: 28
yes , you can achieve the same result using access lists by permiting some kind of traffic to the specified host, but access list is not secure as a dedicated firewall.

give more info if u can


Top
 Profile  
 
 Post subject:
PostPosted: Mon Jul 25, 2005 7:04 am 
Offline
New Member
New Member

Joined: Mon Jul 25, 2005 6:18 am
Posts: 6
Image

I would like all the access lists that would be needed to make the DMZ as secure as possible.


Top
 Profile  
 
PostPosted: Mon Jul 25, 2005 9:16 am 
Offline
New Member
New Member
User avatar

Joined: Wed Feb 16, 2005 6:48 am
Posts: 17
Location: London
Hi,

What sort off access do you need from the internet/inside to the DMZ and vice versa?

If I see correctly in the diagram(PS! What application you use for the drawing???) you have an 1800 router.

Does it have the firewall feature set?
That has some good firewall features if you have the correct IOS, coupled with access-lists should be no problem.

Let us know!

Rob


Top
 Profile  
 
 Post subject:
PostPosted: Tue Jul 26, 2005 5:10 am 
Offline
New Member
New Member

Joined: Mon Mar 21, 2005 2:49 pm
Posts: 28
ok ,

1-do u want to allow access from the private network to the outside or only to the DMZ?

2-are there any special services u need to allow like http,telnet,etc in the DMZ?


Top
 Profile  
 
 Post subject:
PostPosted: Tue Jul 26, 2005 8:24 am 
Offline
Site Admin
Site Admin
User avatar

Joined: Mon Dec 06, 2004 6:46 pm
Posts: 10261
Location: McKinney, TX
Certs: CCNA
Quote:
I would like all the access lists that would be needed to make the DMZ as secure as possible.


access-list 1 deny any

:)

_________________
Find networking-forum.com on Facebook, LinkedIn, Twitter, Google+,or subscribe to the site's RSS feeds.


Top
 Profile  
 
PostPosted: Tue Jul 26, 2005 4:22 pm 
Offline
New Member
New Member
User avatar

Joined: Wed Feb 16, 2005 6:48 am
Posts: 17
Location: London
:lol:
Cant get any more secured than that!


Top
 Profile  
 
 Post subject:
PostPosted: Wed Jul 27, 2005 5:43 am 
Offline
New Member
New Member

Joined: Mon Mar 21, 2005 2:49 pm
Posts: 28
steve finished it :D totally secured


Top
 Profile  
 
 Post subject:
PostPosted: Thu Jul 28, 2005 6:40 am 
Offline
New Member
New Member

Joined: Mon Jul 25, 2005 6:18 am
Posts: 6
I've found a very helpfull article which pretty much gives me everything I need to know.

http://my.execpc.com/~keithp/dmz.htm

Looks good to me. What do you guys think?


Top
 Profile  
 
 Post subject:
PostPosted: Thu Jul 28, 2005 8:18 am 
Offline
New Member
New Member

Joined: Mon Mar 21, 2005 2:49 pm
Posts: 28
well done , thats exactly your case.

but again access lists can be tricked by experinced hackers so its not for securing your network its only for traffic management.

what do u think guys?


Top
 Profile  
 
 Post subject:
PostPosted: Thu Jul 28, 2005 9:04 am 
Offline
New Member
New Member

Joined: Mon Jul 25, 2005 6:18 am
Posts: 6
I agree, to secure the DMZ like this would be nigh on impossible but as long as the internal LAN is secure via the Proxy Server, it's a risk you have to take. My only alternative is to have a tri-homed Proxy Server and let ISA Server foward DMZ, LAN and Internet traffic accordingly. Does anyone here have any experience with this?


Top
 Profile  
 
 Post subject:
PostPosted: Mon Aug 01, 2005 3:49 pm 
Offline
Post Whore
Post Whore
User avatar

Joined: Mon Jan 17, 2005 11:01 pm
Posts: 5148
Location: Canada eh
Certs: 350-001, CCNP, CXFF, ITILv3F
WeStIe wrote:
I would like all the access lists that would be needed to make the DMZ as secure as possible.


Uhh, WTF?

Maybe I'm off base here, but by definition a DMZ in UNSECURE, hence the need for it. A DMZ is someplace you allow untrsuted people to do untrusted things. You then properly firewall after (or before, or whatever angle you happen to be looking from) that as it enters the rest of your network.

I realize I'm most likely being too literal here, but my point is don't fool yourself to thinking you have DMZ that is even remotely secure.


Top
 Profile  
 
Display posts from previous:  Sort by  
Post new topic Reply to topic  [ 12 posts ] 

All times are UTC - 6 hours [ DST ]


Who is online

Users browsing this forum: Blackmail88 and 21 guests


You cannot post new topics in this forum
You cannot reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot post attachments in this forum

Search for:
Jump to:  
Powered by phpBB® Forum Software © phpBB Group