Dual nic with DMZ via firewall



I will be installing sbs standard next week and I would like to setup
the WAN NIC to be in our firewalls DMZ. (currently zywall100 dmz port -
switch -> 2 web servers)

Are there any problems with this? Local web access should continue to
use firewall as gateway, but web facing sbs services like incoming
email or rww would be protected via DMZ firewall rules.

Somehow I feel a lot safer poking holes into the DMZ then onto the
LAN. But then the usual protection of the DMZ doesn't exist anymore.
If the SBS box is compromised then it also exists on the LAN so maybe
it makes no difference. I still think i would prefer to have SBS on
the DMZ so that it can use it's own IP address and not just share the
firewalls. I guess I would rather not have it's IP resolve to any
name either.

Also will there be routing problems with LAN users checking email etc.
if exchange is bound to an external IP?

Thanks for your suggestions/expertise .

(btw zywall100 is a good firewall with a real DMZ port)

.



Relevant Pages

  • Re: SBS2008 Single Single NIC only
    ... Using the "DMZ" concept is probably the best idea. ... the rest of the network. ... Calyptic firewall has 3 extra ports that I can configure. ... You had to go thru the SBS firewall or Natting to get ...
    (microsoft.public.windows.server.sbs)
  • Re: Dual nic with DMZ via firewall
    ... the WAN NIC to be in our firewalls DMZ. ... email or rww would be protected via DMZ firewall rules. ... If the SBS box is compromised then it also exists on the LAN so maybe ... (btw zywall100 is a good firewall with a real DMZ port) ...
    (microsoft.public.windows.server.sbs)
  • Re: Network Setup for SBS with 2 NICs Behind Firewall
    ... The main 'problem' here is the SBS wizards. ... DHCP on SBS will not offer the firewall as a route but SBS ... The DMZ port of the firewall will be temporarily ignored. ...
    (microsoft.public.windows.server.sbs)
  • Re: Dual nic with DMZ via firewall
    ... the WAN NIC to be in our firewalls DMZ. ... email or rww would be protected via DMZ firewall rules. ... If the SBS box is compromised then it also exists on the LAN so maybe ... If you have the SBS server WAN port in the DMZ and your Firewalls LAN is ...
    (microsoft.public.windows.server.sbs)
  • Ang: RE: Firewall and DMZ topology
    ... Network Engineer ... Subject: Firewall and DMZ topology ... > The Gartner Group just put Neoteris in the top of its Magic Quadrant, ...
    (Security-Basics)