Re: dhcpd in dmz ?

From: David Efflandt (efflandt_at_xnet.com)
Date: 10/28/04


Date: Wed, 27 Oct 2004 23:47:37 +0000 (UTC)

On Wed, 27 Oct 2004 13:09:50 +0200, peter pilsl <pilsl@goldfisch.at> wrote:
>
> We currently have one server that provides dhcpd, bind, smtp, imap, web
> ... for our LAN. Now we want to open imap/web for access from the
> outside too and think about moving this server to the DMZ.
>
> Does that make sense? Is it technically possible with common firewalls?
> (at the moment we use a softwarefirewall, but we think about switching
> to a hardwarefirewall like the zyxel ZyWall50) Especially dhcpd bothers
> me, cause I dont have any idea if it is possible to "open" a door for
> arp between the DMZ and the intranet. To me it sounds like this would
> spoil the whole sense of DMZ.

>From the view of SuSEfirewall2 a DMZ should be public IPs on a separate
nic (which might or might not be allowed direct communication with LAN).
Although, broadband routers have the view that a DMZ is a single IP that
receives all incoming ports not specifically forwarded to other IPs.

But in order for a server to work, it should have a static IP (so your
firewall knows where to forward incoming public traffic). You can assign
a static IP using dhcp based on MAC address. But much easier to simply
configure the server with static IP, gateway and DNS.



Relevant Pages

  • Re: Web portal security
    ... win2003 standard server with IIS, SSL enabled and will be placed on ... So I will be fwding port 443 in firewall to my DMZ port. ... Well, assuming you are going to use teh SQL database from SBS, you can ... subnet than my LAN and map one to one from firewall to dmz. ...
    (microsoft.public.windows.server.sbs)
  • Re: 2 NICs Configuration Problem
    ... Servers on the DMZ are public, ... provides NAT for the LAN machines, allowing them to reach the Internet ... effectively bypassing firewall filtering to that server. ... Ethernet adapter Server Local Area Connection: ...
    (microsoft.public.windows.server.networking)
  • Re: Where to put the server
    ... Put the 2003 IIS Server in the DMZ. ... SBS box or another LAN server. ...
    (microsoft.public.backoffice.smallbiz2000)
  • Re: Hosting, in or out?
    ... proprietary SQL based application is the core of the business. ... A new requirement calls for a report only server, ... SBS LAN is called PRIVATE or LAN ... Web LAN is called RESTRICTED or DMZ ...
    (microsoft.public.windows.server.sbs)
  • Re: Groklaws "Bias" and the SCO DDoS Attack
    ... >on the same local LAN your office machines are you can congest that ... routers, with port 80 redirected to a web server on the LAN side. ... I've also used Sonicwall DMZ routers. ...
    (comp.unix.sco.misc)