Questions tagged [dmz]

In computer security, a DMZ, or demilitarized zone is a physical or logical subnetwork that contains and exposes an organization's external services to a larger untrusted network, usually the Internet. The term is normally referred to as a DMZ by information technology professionals. It is sometimes referred to as a perimeter network.

In computer security, a DMZ, or demilitarized zone is a physical or logical subnetwork that contains and exposes an organization's external services to a larger untrusted network, usually the Internet. The term is normally referred to as a DMZ by information technology professionals. It is sometimes referred to as a perimeter network.

The purpose of a DMZ is to add an additional layer of security to an organization's local area network (LAN); an external attacker only has access to equipment in the DMZ, rather than any other part of the network.

204 questions
2
votes
1 answer

Automatically ask router for port redirection on ubuntu

Is there a way to use uPnp or something to automatically ask a router/firewall to redirect data coming from outside to a machine running ubuntu? Here's the deal, I'm supposed to prepare a certain number of machines, which will act as kiosks, and…
ddrocks
  • 29
  • 2
2
votes
2 answers

Setup DMZ in Pfsense with virtual servers, physical Pfsense server

I am looking for some networking tips on how to set up a DMZ in Pfsense and place some virtual servers in that DMZ. Right now my network looks like: Uverse (Static IPs) -> Pfsense -> WAN -> (Virtual IPs/CARP/NAT 1:1 to virtual server's internal IP…
user1212436
  • 21
  • 1
  • 3
2
votes
0 answers

Deploying a ASP.Net WebAPI website and DMZ

I have a set of RESTful services developed using ASP.Net WebAPI which is a single project. I handle authentication via ASP.Net's built in Forms Authentication (cookie based) mechanism which is also built into the same project. The services need to…
Harindaka
  • 121
  • 1
2
votes
1 answer

How to Deploy an ASP.NET Web API- and Browser-based Application to a Production Environment

(Please forgive if this is posted in an incorrect forum. We didn’t know exactly where to post it.) We have an ASP.NET Web API single page application - a browser-based app running in IIS to serve up HTML5/CSS3/JavaScript, which talks to the ASP.NET…
lmttag
  • 197
  • 1
  • 3
  • 8
2
votes
2 answers

Do I need to place a physical server/host within the DMZ to host servers/applications?

We are moving to a new office, and part is to review our current LAN/WAN and server access to/from the web. I understand how the DMZ works, but can't figure out if I need a physical server/host to be placed between my 2 firewalls, or I can do with…
Saariko
  • 1,791
  • 14
  • 45
  • 75
2
votes
2 answers

Internal traffic card and external traffic cards on the same server... how to configure?

This might sound like a noob question, but here is what I have to configure: FreeBSD 1 server with 2 network cards 1 network card for internal IP addresses (5 of them) 1 network card for external IP addresses (3 of them) the server is the DNS…
Fabrizio
  • 73
  • 1
  • 7
2
votes
2 answers

Reverse Proxy - should it be a different technology stack?

Got a skeptical question about a reverse proxy setup I'm considering. I've currently got a pair of load balanced application servers in the DMZ (S1,S2 in figure below). These accept inbound requests from external clients. They also connections to…
Happyblue
  • 75
  • 1
  • 8
2
votes
3 answers

Webservers - Attached to AD or not?

Do you prefer to run their IIS webservers inside a DMZ that is part of the greater organisation's AD or do you prefer to sacrifice ease of management and user control over (possibly perceived) security? We currently run our IIS boxes outside of the…
mjallday
  • 924
  • 2
  • 8
  • 14
2
votes
1 answer

Howto maximize utilization of assigned subnet block for DMZ

I'm part time sysadmin for a small hosting company with currently 20 different public servers. We have a 27 subnet block that gives us a maximum of 30 usable IP addresses. That much I know, but how do I maximize the number of IPs I can use for the…
hansfn
  • 195
  • 1
  • 7
2
votes
2 answers

What would a simple DMZ look like for scenario of database server and (web server+middle tier)?

I have two Linux servers: The first contains an Oracle 11G database that includes an Oracle HTTP Server The second contains a Java middle tier plus Apache webserver and Apache Tomcat. Someone mentioned to me I should consider a DMZ. The goal is…
gkdsp
  • 582
  • 1
  • 6
  • 19
2
votes
3 answers

ASA: How to connect server with a external IP address already assigned?

Any ideas how this can be done on a ASA? There was a sonicwall in place but it just died and we do not have a replacement besides this ASA. The 24.172.x.132 is a spam filter and I can't change the IP address. It needs to be able to access one…
evolvd
  • 1,384
  • 6
  • 33
  • 58
2
votes
3 answers

Accessing Internet from the DMZ

I am trying to configure a DMZ using IPCop but it looks like the default configuration for a DMZ in IPCop is no DHCP and no access to Internet. Even when I manually configure IPCop as my default gateway and DNS resolver, it seems that there is no…
Vincent Robert
  • 194
  • 3
  • 13
2
votes
4 answers

To DMZ or not-DMZ on new web site

We are about to release a web application for our users, and are trying to figure out if others put their servers in a DMZ, or just keep it off the domain behind the firewall and greatly restrict access via firewall rules? Has anyone here found any…
Beep beep
  • 1,833
  • 2
  • 18
  • 33
2
votes
3 answers

network topology including many services

I know this is yet another question on how to setup network but I hope you are not bored of such questions yet. The site is also an office, so it includes windows dc, windows ad, exchange, sql, file sharing, development app servers and other pcs. In…
mete
  • 157
  • 5
2
votes
4 answers

Putting a Windows DC, Exchange in a DMZ

I have one guy at my company telling me that I should put FF:TMG in between my main Internet-facing firewall (Cisco 5510) and put my Exchange server and DC on the internal network. I have another guy telling me that I should put the Exchange server…
blsub6
  • 1,131
  • 6
  • 25
  • 45