Re: back to back DMZ

Tech-Archive recommends: Fix windows errors by optimizing your registry



"jimi hendrix" <jimihendrix@xxxxxxxxxxxxxxxxxxxxxxxxx> wrote in message
news:941D50CF-E147-4502-8D9C-B15E7CC6CFF8@xxxxxxxxxxxxxxxx
How secure is this , when the servers are on my LAN then a hacker is right
in
my internal network,..
or does isa 2006 makes it work,..

Then what good is the DMZ? The Servers still have to talk to the LAN,..if
he has control of the servers he can communicate with whatever they can
communicate with.

Your *real* security lies with the Servers being used,...not the Firewall
making them available, or the DMZ you stick them in.

--
Phillip Windell
www.wandtv.com

The views expressed, are my own and not those of my employer, or Microsoft,
or anyone else associated with me, including my cats.
-----------------------------------------------------
Understanding the ISA 2004 Access Rule Processing
http://www.isaserver.org/articles/ISA2004_AccessRules.html

Troubleshooting Client Authentication on Access Rules in ISA Server 2004
http://download.microsoft.com/download/9/1/8/918ed2d3-71d0-40ed-8e6d-fd6eeb6cfa07/ts_rules.doc

Microsoft Internet Security & Acceleration Server: Partners
http://www.microsoft.com/isaserver/partners/default.asp

Microsoft ISA Server Partners: Partner Hardware Solutions
http://www.microsoft.com/forefront/edgesecurity/partners/hardwarepartners.mspx
-----------------------------------------------------


.



Relevant Pages

  • Re: Domain in ISA2004 dmz
    ... put services that are needed to 'listen' for incoming internet requests ... DMZ trusts Seattle.Demo but seattle.demo does ... > Would it just be better if we left nothing but the web servers in the dmz ...
    (microsoft.public.isa)
  • Re: Where to place the DMZ zone?
    ... hypothetically lets say you have no DMZ hosting an email bridgehead ... If a hacker were to compromise one of your email or web servers (they are ... That is, the Internet accessible servers ... that can be compromised are on your internal network, ...
    (microsoft.public.isa)
  • Re: ISA 2006 web proxy scenario
    ... The 4 servers are in 2 separate DMZ's - see below. ... internal array and having all traffic handled by the external array. ... You now have a Back-to-Back DMZ sitting between the ISA Array and the PIX. ... Microsoft Internet Security & Acceleration Server: ...
    (microsoft.public.isa)
  • Re: Real IPs
    ... First, I'm assuming you have servers which serve incoming ... connections from the internet. ... How you configure your DMZ is up to you, ... Iptables masquerades your lan traffic for you. ...
    (linux.redhat)
  • Re: CheckPoint + ISA2004 Nating
    ... servers.If those servers in DMZ segment have been nated then the Incomming ... You should modify the NATs on your Checkpoint so that all traffic is ... forwarded to the external interface IP of ISA instead of individual ...
    (microsoft.public.isa.configuration)