Re: hardware firewall with SBS



Rick,

If the TZ170 is capable of port forwarding and NAT, which a $20 router will
do, then it should work just fine. Your diagram is right on the money and is
precisely how mine is set up. If you use a DMZ on most routers, it is
equivalent to putting the server live on the Internet. I am not sure of the
SonicWall's DMZ settings, though.

You are correct. Collect your money!

Gregg Hill


"Rick" <Rick@xxxxxxxxxxxxxxxxxxxxxxxxx> wrote in message
news:3E3D7338-2421-48FE-AB67-84D4D95FAEAA@xxxxxxxxxxxxxxxx
> Hi All,
>
> I am re-arranging my network in hopes of a higher level of security. I've
> previously posted questions asking if SBS security is enough and it seemed
> a
> good percentage of admins out there recommend still having a hardware
> firewall. So I have bought a device that comes highly recommended for
> small
> businesses -- a SonicWall TZ 170.
>
> I'm a little disappointed in the SonicWall's documentation. It is very
> poor
> with respect to a "start here for firewalling basics" section -- there
> isn't
> one.
>
> A friend of mine with his own small business has a TZ 170 and he swears
> that
> your servers on the public Internet have to plug in the "Option" or DMZ
> zone
> port on the device. But he doesn't have SBS with it's dual-homed setup.
>
> I'm thinking the following makes the most sense for SBS:
>
> (Internet)
> |
> [DSL modem]
> |
> | WAN port
> [TZ 170]
> | LAN port (not Opt)
> |
> | SBS external interface
> [SBS 2K3]
> | SBS internal interface
> |
> [10/100/1000 switch]
> | | | | | | | | |
> (Internal worstations and servers)
>
> Am I right, or is my friend? You would think I could look up the answer
> to
> this kind of question in the SonicWall documentation, but it's not there.
> It
> does not describe at all what the "Opt" port is really for beyond the
> following:
>
> "Configuring the OPT Port in Transparent Mode
>
> If your ISP provided you with enough IP addresses for all the computers
> and
> network devices on your OPT, enable Transparent Mode. To configure
> Transparent mode, complete the following instructions:
> 1) ...
> 2) ...
> ... etc ....
>
> Configuring the OPT Port in NAT Mode
>
> If your ISP has not given you enough IP addresses for all of the computers
> and network devices on your OPT, you can configure the SonicWall to use
> NAT
> Enabled mode. ....etc..."
>
>
> Incredibly bad documentation in that nowhere does it describe what the OPT
> port is actually for.
>
> I know this fairly hardware-related question, but the reason for the
> question is because the OS is SBS 2K3.
>
> Any help or insights will be very appreciated.
> Thanks,
>
> -Rick


.



Relevant Pages

  • Re: snfs factorization of a 1039-bit number
    ... the recruitment will opt apart from the inadequate ... port. ... How doesn't Abdellah come severely? ...
    (sci.crypt)
  • Re: Virtual Server on SBS2003 Prem
    ... I was not familiar with constrained delegation so i did not opt for it. ... either accept the default Website port ... From the VS2005 R2 help file, "Securing Virtual Server"; ...
    (microsoft.public.windows.server.sbs)
  • Re: [SLE] gnutella firewalled on 6346
    ... WINDOW=16968 RES=0x00 ACK SYN URGP=0 OPT ... > what port fw is dropping? ... Check the headers for your unsubscription address For additional commands send e-mail to suse-linux-e-help@suse.com Also check the archives at http://lists.suse.com Please read the FAQs: suse-linux-e-faq@suse.com ...
    (SuSE)
  • RE: Port Forwarding With 2 NIC Configuration
    ... Can SBS do 1-to-1 Natting? ... > and incoming/outgoing port, ... > automatically redirected from the SBS server to port 81 of the internal ... > Microsoft CSS Online Newsgroup Support ...
    (microsoft.public.windows.server.sbs)
  • Re: Weird 529 Errors in Security Log
    ... Les Connor [SBS MVP] ... Port 80 has always been closed on both my router/firewall and ISA 2004. ... click to check the "Hide All Microsoft ... This newsgroup only focuses on SBS technical issues. ...
    (microsoft.public.windows.server.sbs)