Port Forwarding or DMZ

Hello all, My network is currently using NAT with a basic sonicwalll pro 100 firewall. I have 2 new webservers to implement. i am going to purchase a cisco 515e. This is kind of my first time setting up webservers on a network. Is it better to set them on a DMZ or have it sit behind the firewall and have the ports forwarded? all advice is appreciated.
mrlucio79Asked:
Who is Participating?

Improve company productivity with a Business Account.Sign Up

x
 
lrmooreConnect With a Mentor Commented:
The 515 can handle up to 6 interfaces, or 4 DMZ's

Internet
    |
  Router
     |
  PIX Outside           Whatever you want the DMZ's to be....this is just an example
            DMZ1 ----- Web servers
            DMZ2 ----- Extranet connections
            DMZ3 ----- Special purpose servers (VPN)
            DMZ4 ----- reserved for future use
   PIX inside
       |
    Internal network
       |
    Internal router ----- intranet WAN remote sites
0
 
lrmooreCommented:
It is always considered best practice to put any server that is publicly accessible on a DMZ.
0
 
mrlucio79Author Commented:
How many DMZs can the Cisco 515E handle? What do you think about this setup:

Internet<------>external router<------>Webserver(DMZ)<------>Firewall<------>internal router
<------>Network
0
The Lifecycle Approach to Managing Security Policy

Managing application connectivity and security policies can be achieved more effectively when following a framework that automates repeatable processes and ensures that the right activities are performed in the right order.

 
mrlucio79Author Commented:
Nice description! :0)  Here is a very stupid question though: Is it possible that I could hook a cisco switch into DMZ1 to host mutliple web servers?
0
 
lrmooreCommented:
Absolutely! You can connect any interface to a switch. You can have 1000 servers on any DMZ that you want...
0
 
mrlucio79Author Commented:
gotcha. This is great info. Thanks!!!
0
Question has a verified solution.

Are you are experiencing a similar issue? Get a personalized answer when you ask a related question.

Have a better answer? Share it in a comment.

All Courses

From novice to tech pro — start learning today.