From: /dev/rob0 <rob0@gmx.co.uk>
To: netfilter@lists.netfilter.org
Subject: Re: DMZ Setup Question
Date: Wed, 30 Nov 2005 13:51:11 -0600 [thread overview]
Message-ID: <200511301351.11306.rob0@gmx.co.uk> (raw)
In-Reply-To: <FAC4E024BF776842876169173CE2F01313B204@mailbox.vikus.com>
On Wednesday 2005-November-30 12:32, Derick Anderson wrote:
> My inclination would be to use NAT (MASQUERADE) for your internal
> hosts just because it makes things simpler (not necessarily more
> secure) and your DMZ doesn't need routes to your internal network.
> Some may say then that simpler is more secure and I agree, but I
> still say that NAT is a routing tool and not a security tool.
The only potential security issue is one that SHOULD have already been
addressed by disabling packet forwarding on the DMZ machines, and that
is that an upstream attacker might route packets to your LAN machines
using [a] DMZ machine[s] as gateway.
Otherwise I agree with you and Derick. I prefer routing when it's a
possibility.
Even without the LAN routes the DMZ machines should not allow packet
forwarding.
--
mail to this address is discarded unless "/dev/rob0"
or "not-spam" is in Subject: header
next prev parent reply other threads:[~2005-11-30 19:51 UTC|newest]
Thread overview: 4+ messages / expand[flat|nested] mbox.gz Atom feed top
2005-11-30 18:32 DMZ Setup Question Derick Anderson
2005-11-30 19:51 ` /dev/rob0 [this message]
-- strict thread matches above, loose matches on Subject: below --
2005-11-30 16:22 Jay Zorzi
2005-12-06 13:04 ` Nick Drage
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=200511301351.11306.rob0@gmx.co.uk \
--to=rob0@gmx.co.uk \
--cc=netfilter@lists.netfilter.org \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.