Modern Three Interface Firewall Design
Most designs today use the topology shown in Figure 7-6. This design has become the current gold standard in firewall edge deployments. More-secure options exist (see the next design), but this is the best balance of security, cost, and management.
Figure 7-6. Three-Interface Firewall Design
Figure 7-6. Three-Interface Firewall Design
The biggest benefit this design provides is requiring that all traffic flow through the firewall. This includes traffic from the Internet to the public servers, which in all previous designs were only protected by a router with ACLs. For example, if an attacker finds an exploit that allows one of your public servers to be compromised (after the attacker gets through the firewall the first time), the attacker still must go back through the firewall (using a different filtering policy) to attack your internal systems.
This design can be modified by adding more segments off of the firewall, allowing public servers to be separated from one another.
Continue reading here: Figure SS Single Local DNS Server
Was this article helpful?
Readers' Questions
-
fethawi yusef7 months ago
- Reply