Re: Add DMZ



It's a way to import all my rules after switch to 3-legged firewall?
Or i have to do it manually?
Tks for reply and help
JFB

"ZVR" <no_spam_ever@xxxxxx> wrote in message
news:442af2ce$0$5443$9a6e19ea@xxxxxxxxxxxxxxxxxxxxxxxxxxxx
Yes I saw this articles... I wan to do The Trihomed DMZ
But How do I configure my DMZ nic???

If you have a class of valid (public) IP's you want to use on the DMZ,
then you assign one IP from that class to the DMZ NIC and set the
relationship between "DMZ" and "External" to "Route" in the ISA console.

If you want to use private addresses on the DMZ then you pick one private
subnet that's outside your LAN range, assign an IP from that subnet to the
DMZ NIC, and set the relationship between "DMZ" and "External" to NAT.

Regarding your other question, yes after you install the 3rd NIC you
should change the network template to "3-legged firewall". Careful that
when you do that all existing firewall rules will be deleted and you'll
have to recreate the config from scratch.

Virgil




.



Relevant Pages

  • Ang: RE: Firewall and DMZ topology
    ... Network Engineer ... Subject: Firewall and DMZ topology ... > The Gartner Group just put Neoteris in the top of its Magic Quadrant, ...
    (Security-Basics)
  • RE: Firewall and DMZ topology
    ... Subject: Firewall and DMZ topology ... Should the DMZ be behind the LAN and not split off at the firewall, ... > The Gartner Group just put Neoteris in the top of its Magic Quadrant, ...
    (Security-Basics)
  • RE: Basic Network Configuration
    ... - between the internet and the DMZ subnet ... - between the internet and the trusted subnet ... Ignoring, for the moment, vulnerabilities in the firewall ... If, instead, you use two boxes, your traffic between the ...
    (Security-Basics)
  • RE: Firewall and DMZ topology
    ... Subject: Firewall and DMZ topology ... Also, when I say firewall, I mean Router + Firewall. ... Should the DMZ be behind the LAN and not split off at the firewall, ... > The Gartner Group just put Neoteris in the top of its Magic Quadrant, ...
    (Security-Basics)
  • Re: Unable to join AD domain from DMZ network
    ... To me that points to something outside the machine (Firewall most likely culprit) ... > the captured traffic between the server in DMZ to the DC from internal ... >>> authentication from DMZ to 2003 AD internal network. ...
    (microsoft.public.windows.server.active_directory)