Re: Any reason for 2nd NIC w/hardware firewall?



The FIREBOX will be a VPN endpoint, the only public ports will be for OWA and
moble devices, and maybe a future hosted website (but more then likely not).

I'm thinking the 2nd NIC is just going to complicate matters?


"Les Connor [SBS Community Member - SBS M" wrote:

Yes, it would be redundant. But then again so is having two power supplies
and redundant disks ;-).

About the only circumstance where you'd purposely avoid two nics would be if
you're using your hardware device as a VPN endpoint. You don't *have* to go
with two nics, but it does give you some additional flexibility, such as an
internet connection point that's outside your lan - which is handy in quite
a few circumstances.

--
Les Connor [SBS Community Member - SBS MVP]
-----------------------------------------------------------
SBS Rocks !
----------------------
"Tell me and I'll forget. Show me and I'll remember. Involve me and I'll
understand." - Confucius


"Daveinfla" <Daveinfla@xxxxxxxxxxxxxxxxxxxxxxxxx> wrote in message
news:483EFD95-8392-486F-984C-3565DA6C51CF@xxxxxxxxxxxxxxxx
Got it, with this in mind using 2 NIC's and the basic firewall (Standard
Edition) behind a Firebox would be redundant?

"SuperGumby [SBS MVP]" wrote:

a firewall does not just open/close ports, it inspects traffic travelling
through open connections and only allows them to remain open if defined
criteria are met. One of the reasons I prefer SBS Premium is due to ISA
'Application layer' traffic filtering. This means that you can control
not
only the type of traffic but exactly which process requests it. Opening a
port is not necessarily opening a port :-)

"Daveinfla" <Daveinfla@xxxxxxxxxxxxxxxxxxxxxxxxx> wrote in message
news:644E279C-963B-4F19-A1B1-0CF37BFD8C24@xxxxxxxxxxxxxxxx
It's a firebox, but can you elaborate a bit on the difference?

I know a True firewall gives added protection, but opening a port is
opening
a port NAT or no NAT, isn't it?

And what does the 2 NIC option provide behind a NAT firewall?

Thanks,



"SuperGumby [SBS MVP]" wrote:

The desirability for a 2 NIC setup depends largely on the capabilities
of
the 'firewall' device.

If it is a true firewall device there is little benefit in running a
two
NIC
solution. (Read WatchGuard FireBox, Cisco PIX or similar)

If it is a simple NAT router (which many incorrectly refer to as a
firewall)
a 2NIC solution is desirable.

"Daveinfla" <Daveinfla@xxxxxxxxxxxxxxxxxxxxxxxxx> wrote in message
news:B9A64BB6-E454-4123-B2E9-6D66E52E83A8@xxxxxxxxxxxxxxxx
Setting up a new SBS 2003 Standard server (is that redundant?),
which
has
two
NIC's, however the 2nd is currently disabled since it's behind a
hardware
firewall/VPN router.

Plans are to allow OWA, and possibly host a website in the future;
all
other
traffic will be via VPN.

Is there any reason to use the 2nd NIC and the built-in firewall on
SBS?

Thanks











.



Relevant Pages

  • Re: SBS 1002 Premium R2 Mangling Port Issues
    ... The ADT remote camera view is working ... configure SBS), or you can configure SBS to use both NICs and then re-run ... If choose two NICS, the WAN NIC and the LAN side of the router must ... + Now forward the port 8016 traffic from the external SBS NIC to the LAN ...
    (microsoft.public.windows.server.sbs)
  • Re: SBS 1002 Premium R2 Mangling Port Issues
    ... For solutions like forefront, I am unsure why MS is not using the Windows ... When we use the term "hardware" firewall, ... The direction now is hardware firewall in front of SBS. ... NIC or 2 NICs) did you finally end up with? ...
    (microsoft.public.windows.server.sbs)
  • Website setup questions.
    ... Create firewall rule to direct HTTP port 80 to the SBS External NIC ... Create firewall rule to point DNS port 53 to the SBS External NIC ... NICS to get this request to not timeout or be refused. ...
    (microsoft.public.windows.server.sbs)
  • Re: May need to move from SBS because of connection issues
    ... Just to make sure you are clear regarding port 4125, ... access remote systems and you are behind a firewall on a non-SBS network, ... established that RWW worked TO your SBS network from outside. ... have been proof that the required ports were forwarded to the SBS server. ...
    (microsoft.public.windows.server.sbs)
  • Re: SBS 1002 Premium R2 Mangling Port Issues
    ... When we use the term "hardware" firewall, ... The direction now is hardware firewall in front of SBS. ... your users or use some other feature of ISA). ... NIC or 2 NICs) did you finally end up with? ...
    (microsoft.public.windows.server.sbs)

Loading