Firewall Wizards mailing list archives

Design Question


From: "James Wilson" <netsurf () sersol com>
Date: Fri, 3 Jul 1998 18:53:05 -1000

-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

Aloha,

After doing some research I've got a design to protect an additional
connection to the internet while protecting our private network and
private WAN link.  This additional connection will not be the primary
internet gateway but will be used for H.323 and H.320 Telemedicine
applications, and to host a non-secure webserver in the DMZ.  I like
the Cisco Firewall IOS combined with the PIX for speed, statefull
filtering, detection of attacks, and IPSec support.  The router will
drop connections and packets when attacks are detected.  If anything
gets by the router, the secure traffic will be encrypted, and the PIX
firewall will also protect the private network and support the
encrypted traffic.  The 10mb switch in the DMZ is to separate the web
server from the other 2514 ethernet port traffic. Do you have any
observations or suggestions?  It will look like this:   
  
      Cisco 2514 running the latest Firewall IOS Featureset w/DoS
detection, 56B
      IPSEC encryption; WAN port to Internet
                                  E0 and E1 connected to a 10mb switch

      The PIX secure webserver port will connect to the 10mb
      switch, as will the second ethernet port.  The second ethernet
      port will have a IPSEC connection between it and the 2514, and
      the 2514 will have IPSEC connections available to the
telemedicine partners.
     Telnet and ascii containing sessions will be encrypted; image
data will be
     compressed but not encrypted.  The non-secure connection to the
webserver
     will not be encrypted and no sensitive or critical info/services
will be supported
     on it.

      The private side of the PIX will connect to our 100FX Ctron 6600
backbone

Periodic scans (both internal and external) will be run, and RMON
alerts will be monitoring the Firewall and inside routers and will
alert us via pagers & popup windows on consoles.  Since we are 7:30 -
4:00 M-F, the router connection to the Internet will automatically be
started up weekdays at 7:30 am and shutdown evenings at 4:00pm and
kept down over the weekend and holidays.

In order to get this approved with our Wash. D.C. security office we
have to submit a complete package with contingency plans,
identification of sensitive vs. non-sensitive servers and
applications, documentation of our security policies and procedures,
and committment from our Director to support the firewall and
applications.

Does this sound like a workable configuration balancing security and
function?

Mahalo! (Thanx)

- -
James Wilson

-----BEGIN PGP SIGNATURE-----
Version: PGPfreeware 5.5.5 for non-commercial use <http://www.nai.com>
Comment: Support the Smith Anti-Spam Bill and Ban Junk Email

iQA/AwUBNZ21MTAufbtGOmgdEQKPAwCgxbimaGAgTOaMrKqrWYwqadM4XO0An1N4
W8KGKipsCe52VkJP5xTnpyL0
=Fale
-----END PGP SIGNATURE-----




Current thread: