Best method to secure traffic within a DMZ


we have internal , external facing firewall, have firewall access lists specify boxes 3rd party company can to, have problem of limiting access other boxes exisit within dmz once 3rd party have got access original server.

options have thought of are:

1. firewall in between every group of servers 3rd parties require access to, creating dmz each 3rd party. won't work though, because servers require access multiple 3rd parties.

2. vlan in between every group of servers 3rd parties require access to, creating virtual dmz each 3rd party. won't work though, because servers require access multiple 3rd parties.

3. create new ad forest within dmz, , use group policies deploy ipsec policies each server required.

4. install software firewall on each server , set relevant rules.

can ask how other companies out there, resolve or reduce risk issue.

thanks

kev


kevin evans



Windows Server  >  Security



Comments

Popular posts from this blog

2008 Windows Deployment Server Properties Error

Domain migration ERR3:7075 Failed to change domain affiliation, hr=8007054a This operation is only allowed for the Primary Domain Controller of the domain

How do a find data in one file, search for it in another file and if not found, write a custom message to another file