All of lore.kernel.org
 help / color / mirror / Atom feed
From: /dev/rob0 <rob0@gmx.co.uk>
To: netfilter@lists.netfilter.org
Subject: Re: DMZ Setup Question
Date: Wed, 30 Nov 2005 13:51:11 -0600	[thread overview]
Message-ID: <200511301351.11306.rob0@gmx.co.uk> (raw)
In-Reply-To: <FAC4E024BF776842876169173CE2F01313B204@mailbox.vikus.com>

On Wednesday 2005-November-30 12:32, Derick Anderson wrote:
> My inclination would be to use NAT (MASQUERADE) for your internal
> hosts just because it makes things simpler (not necessarily more
> secure) and your DMZ doesn't need routes to your internal network.
> Some may say then that simpler is more secure and I agree, but I
> still say that NAT is a routing tool and not a security tool.

The only potential security issue is one that SHOULD have already been 
addressed by disabling packet forwarding on the DMZ machines, and that 
is that an upstream attacker might route packets to your LAN machines 
using [a] DMZ machine[s] as gateway.

Otherwise I agree with you and Derick. I prefer routing when it's a 
possibility.

Even without the LAN routes the DMZ machines should not allow packet 
forwarding.
-- 
    mail to this address is discarded unless "/dev/rob0"
    or "not-spam" is in Subject: header


  reply	other threads:[~2005-11-30 19:51 UTC|newest]

Thread overview: 4+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2005-11-30 18:32 DMZ Setup Question Derick Anderson
2005-11-30 19:51 ` /dev/rob0 [this message]
  -- strict thread matches above, loose matches on Subject: below --
2005-11-30 16:22 Jay Zorzi
2005-12-06 13:04 ` Nick Drage

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=200511301351.11306.rob0@gmx.co.uk \
    --to=rob0@gmx.co.uk \
    --cc=netfilter@lists.netfilter.org \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.