DMZ & Proxy Firewall

DMZ & Proxy Firewall

Post by David Masso » Fri, 20 Oct 2000 15:59:17



I have a Linux proxy firewall protecting my internal LAN.  IP forwarding and
some other networking functions have been removed from the kernel and all is
working fine.

I  now want to introduce a DMZ so was planning on putting a third network
card in my firewall and thus creating a another subnet for the DMZ.  The
problem is to access this network from my internal/external networks I need
to enable IP forwarding to route from these interfaces to the new one.

Is this the correct way do do things?  I was under the impression that IP
forwarding was to be kept off the a proxy firewall?

Help appreciated

 
 
 

DMZ & Proxy Firewall

Post by Cedric Blanche » Fri, 20 Oct 2000 04:00:00




Quote:> I have a Linux proxy firewall protecting my internal LAN.  IP forwarding
and
> some other networking functions have been removed from the kernel and all
is
> working fine.

> I  now want to introduce a DMZ so was planning on putting a third network
> card in my firewall and thus creating a another subnet for the DMZ.  The
> problem is to access this network from my internal/external networks I
need
> to enable IP forwarding to route from these interfaces to the new one.

> Is this the correct way do do things?  I was under the impression that IP
> forwarding was to be kept off the a proxy firewall?

With a DMZ, your box will not be a proxy/firewall, but a
router/proxy/firewall. If you do not want to act like this, you'll have to
get a new 2 ifaces box and act like this :

    Internet
        |
    New Box (ip_forward ok, filtering)
        |
        |-------- DMZ
        |
    Proxy/Firewall
        |
    Your LAN

Like this, your DMZ will only be a new perimeter outside your LAN and won't
hurt your LAN security. Moreover, the new box, with a good filtering ruleset
will protect DMZ and enhance Proxy/Firewall box security by limiting
incoming access.

 
 
 

1. DMZ & Proxy Firewall

I have a Linux proxy firewall protecting my internal LAN.  IP forwarding and
some other networking functions have been removed from the kernel and all is
working fine.

I  now want to introduce a DMZ so was planning on putting a third network
card in my firewall and thus creating a another subnet for the DMZ.  The
problem is to access this network from my internal/external networks I need
to enable IP forwarding to route from these interfaces to the new one.

Is this the correct way do do things?  I was under the impression that IP
forwarding was to be kept off the a proxy firewall?

Help appreciated

2. Keyboard lights that flash to the load on the machine

3. ftp client proxy ms proxy firewall http proxy unix

4. Mail to News software

5. suse 7.0 firewall & proxy

6. Apache access log entries

7. Setting Up Proxy Server & Firewall (Linux server or workstations)

8. TGUI 9440 & DRAM Speed

9. Setting Up Proxy Server & Firewall

10. Firewalls & Proxy/Tunneling Servers . . . UDP

11. Setting Up Proxy Server & Firewall

12. Redhat5.0's proxy server and firewall proxy