Best method to secure traffic within a DMZ
we have internal , external facing firewall, have firewall access lists specify boxes 3rd party company can to, have problem of limiting access other boxes exisit within dmz once 3rd party have got access original server.
options have thought of are:
1. firewall in between every group of servers 3rd parties require access to, creating dmz each 3rd party. won't work though, because servers require access multiple 3rd parties.
2. vlan in between every group of servers 3rd parties require access to, creating virtual dmz each 3rd party. won't work though, because servers require access multiple 3rd parties.
3. create new ad forest within dmz, , use group policies deploy ipsec policies each server required.
4. install software firewall on each server , set relevant rules.
can ask how other companies out there, resolve or reduce risk issue.
thanks
kev
kevin evans
Windows Server > Security
Comments
Post a Comment