Re: Svr-03 and DMZ



Bill Grant a utilisé son clavier pour écrire :
A DMZ is behind a firewall. The real difference is what is between the DMZ and the private LAN. If you use the back-to-back firewall model there is an additional firewall between the DMZ and the private LAN.

The best candidates for a DMZ are servers which need to be accessed routinely from the Internet but only occasionally or never from the LAN. Some people like to put things like Exchange or remote access servers in a DMZ but I don't like the idea. It means that you have to open up the inner firewall to allow client machines acccess to the servers in the DMZ.

"BrianMultiLanguage" <BrianMultiLanguage@xxxxxxxxxxxxxxxxxxxxxxxxx> wrote in message news:10EBFA78-700A-43F9-8C3B-0C28DC514887@xxxxxxxxxxxxxxxx
What is a very good reason to put a server, such as a RRAS or any server, on
a DMZ instead of behind a firewall?
Thanks for the input.

For example, some Exchange versions can be configured as a front-end server (to be puted in DMZ) and back-end server (To be puten in the LAN)

So the frond-end server act as a proxy applications to secure WEB Access

RIQUADENT


.



Relevant Pages

  • Re: Securing the DMZ and Trusted domain with a firewall
    ... you can setup firewall to have DMZ completely separate, ... > separated by a Cisco Pix 520 firewall. ... All servers in the DMZ and trusted are multi ... > WINS and DHCP in the trusted domain. ...
    (microsoft.public.security)
  • Re: AD requirements for DMZ?
    ... By standards it is a bad idea to have dc's in a dmz even if they are only used for external access. ... Consider creating a 2008 AD and firewall off the RWDC and provide the RODC's themselves unfettered access to the RWDC. ... In our internal lab environment, we have 3 servers setup as Windows NLB. ...
    (microsoft.public.windows.server.active_directory)
  • RE: Basic Network Configuration
    ... Yes, mail servers, web servers, ftp etc are your DMZ buddies. ... firewall> dmz> firewall> lan layout but physically it does not. ...
    (Security-Basics)
  • Re: Moving servers beind firewall
    ... >> I need to move two servers from outside a firewall to a DMZ. ... >> from both the internet and internal segments. ... I may as well keep those servers outside the ...
    (comp.os.linux.security)
  • Re: how to setup network when many public IPs available ?
    ... firewall for both the DMZ and the private LAN. ...
    (microsoft.public.win2000.ras_routing)