LinuxQuestions.org
Download your favorite Linux distribution at LQ ISO.
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Security
User Name
Password
Linux - Security This forum is for all security related questions.
Questions, tips, system compromises, firewalls, etc. are all included here.

Notices


Reply
  Search this Thread
Old 04-08-2006, 12:07 PM   #1
metallica1973
Senior Member
 
Registered: Feb 2003
Location: Washington D.C
Posts: 2,190

Rep: Reputation: 60
Network Design


If for example you were to create a network that will be providing e-mail,web services and hosting a LAN with users what would be the correct design layout to maximize security?

Example;

Firewall------DMZ----------Web Server
|
|
|
Proxy
|
|
|
LAN
 
Old 04-08-2006, 12:52 PM   #2
Brian1
LQ Guru
 
Registered: Jan 2003
Location: Seymour, Indiana
Distribution: Distribution: RHEL 5 with Pieces of this and that. Kernel 2.6.23.1, KDE 3.5.8 and KDE 4.0 beta, Plu
Posts: 5,700

Rep: Reputation: 65
I myself don't like to interact with web services and lan systems so I built mine this way

Internet
|
eth0
router ( has 3 nics, 1 for wan internet, 1 for dmz servers, 1 for lan)
eth1 lan ---------- eth2 dmz
lan machines----------internet servers

I have gone as far to add a second router between eth1 and lan machines. I have setup wireless access on the second router that has many security features, Mac Filtering, WPA, and radius support. May be extreme but fun to build.
 
Old 04-09-2006, 10:42 AM   #3
pk21
Member
 
Registered: Jun 2002
Location: Netherlands - Amsterdam
Distribution: RedHat 9
Posts: 549

Rep: Reputation: 30
Brian1 isnt that exactly the same configuration as metallica1973 posted?!
 
Old 04-09-2006, 11:46 AM   #4
metallica1973
Senior Member
 
Registered: Feb 2003
Location: Washington D.C
Posts: 2,190

Original Poster
Rep: Reputation: 60
Quote:
Brian1 isnt that exactly the same configuration as metallica1973 posted?!


I have to agree with PK21. I was always taught to put web servers and public services in a DMZ.

Would this be more appropiate and secure?


Firewall/IDS------DMZ----------Web Server
|
|
|
Proxy/Firewall/IDS
|
|
|
LAN

or

Firewall/IDS------DMZ----------Web Server
|
|
|
Proxy/IDS
|
|
|
Firewall/IDS
|
|
|
LAN

Last edited by metallica1973; 04-09-2006 at 11:47 AM.
 
Old 04-09-2006, 05:12 PM   #5
pk21
Member
 
Registered: Jun 2002
Location: Netherlands - Amsterdam
Distribution: RedHat 9
Posts: 549

Rep: Reputation: 30
I think i would go with the first one. But if you have switches which support mirroring of ports then I would go for the following.

|
[switch] ----mirror port to--------------
| |
Firewall------DMZ----------Web Server |
| | |
| | |
[switch] ----mirror port to---------------> IDS
|
Proxy/Firewall
|
|
LAN

Maybe you can mirror switch ports to tap traffic on multiple switches on your network and connect them with an IDS system like snort. With a setup like this traffic will be copied to your IDS and the IDS system doesnt need to send any traffic, it will only recieve traffic and is for this reason more secure then a system that will be reachable from your network.
 
Old 04-09-2006, 05:14 PM   #6
pk21
Member
 
Registered: Jun 2002
Location: Netherlands - Amsterdam
Distribution: RedHat 9
Posts: 549

Rep: Reputation: 30
Damn, my drawings outline didn't stay, lets try again :-) :

|
[switch] ----mirror port to--------------> IDS
|
Firewall------DMZ----------Web Server
|
|
[switch] ----mirror port to---------------> IDS
|
Proxy/Firewall
|
[switch] ----mirror port to---------------> IDS
|
LAN

And ofcourse you can also mirror the traffic which is generated on the DMZ
 
Old 04-09-2006, 11:16 PM   #7
metallica1973
Senior Member
 
Registered: Feb 2003
Location: Washington D.C
Posts: 2,190

Original Poster
Rep: Reputation: 60
Interesting, I will have to read up on port mirroring. thanks
 
  


Reply


Thread Tools Search this Thread
Search this Thread:

Advanced Search

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
m0n0wall + network design kurrupt Linux - Networking 1 11-12-2005 11:40 PM
Is my network design all messed up? DuctTapeNZ Linux - Networking 2 12-20-2004 03:22 AM
Network Design for Larger Network goldcougar Linux - Networking 2 11-21-2003 10:58 AM
what software for network design? realos Linux - Software 2 06-08-2003 04:05 PM
80/20 rule in network design?? Acar Linux - Networking 1 02-19-2002 08:04 AM

LinuxQuestions.org > Forums > Linux Forums > Linux - Security

All times are GMT -5. The time now is 12:18 AM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration