Solved

DMZ with 1 single firewall VS 2 firewall tier

Posted on 2010-11-30
6
1,513 Views
Last Modified: 2012-05-10
Hi,

Could someone help me out to figure this out?

There is a customer that has 1 single firewall and through the rules and interfaces has created a DMZ and then traffic from the DMZ is allowded to the inner network (other VLANs)

Can someone tell me why a 2 firewall tier will be better a better aproach for the DMZ?

Basically : 1st Firewall -> DMZ -> 2nd Firewall ---> inner network  

Thank you!
0
Comment
Question by:llarava
6 Comments
 
LVL 6

Accepted Solution

by:
malkaj01 earned 167 total points
ID: 34239680
The DMZ tier allows you to place the clients that should have the DMZ properties.

This way you can protect your network behind the second firewall.
0
 
LVL 7

Assisted Solution

by:Anglo
Anglo earned 167 total points
ID: 34239882
Both provide the DMZ functionality but the 2nd firewall increases the security of the inner network in the event of the first firewall being compromised.
0
 
LVL 17

Assisted Solution

by:StrifeJester
StrifeJester earned 166 total points
ID: 34240697
Going with the post above and maybe expanding a little.  We use a 2 firewall system here and if you can you should even try to run 2 different vendor firewalls.  This increases the security if one is compromised due to a vulnerability the other may not have that vulnerability.  Also there can be other issues with a "soft" DMZ when it comes to routing from time to time.
0
Free camera licenses with purchase of My Cloud NAS

Milestone Arcus software is compatible with thousands of industry-leading cameras for added flexibility. Upon installation on your My Cloud NAS, you will receive two (2) camera licenses already enabled in the software. And for a limited time, get additional camera licenses FREE.

 

Author Comment

by:llarava
ID: 34263691
Thanks everyone but so far I haven't seen anything that I already didn't know. Let me ask this in a different way...what is the drawback of running at single firewall for the DMZ?
0
 

Author Closing Comment

by:llarava
ID: 34277943
I was looking a better argument.
0
 
LVL 17

Expert Comment

by:StrifeJester
ID: 34282800
I know you closed but I was away all weekend and maybe this will help.  The foremost drawback was mentioned in the fact that using a single firewall increases the chances of a breach.  But it also increases load on your system.  If you have this in an environment where any device has an external IP or you have a range it is going to get hit with port scans and any other number of random events.  Keeping these on the edge will reduce the load on a interior system and can help performance.  If you have a lot in your DMZ that you access from inside the building or through VPNs and things there is a better chance of these services being more reliable since the outer firewall will filter a lot of the junk that is out there.  Hope this helps.
0

Featured Post

PRTG Network Monitor: Intuitive Network Monitoring

Network Monitoring is essential to ensure that computer systems and network devices are running. Use PRTG to monitor LANs, servers, websites, applications and devices, bandwidth, virtual environments, remote systems, IoT, and many more. PRTG is easy to set up & use.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Suggested Solutions

Title # Comments Views Activity
BGP Code 12 42
PCI Compliance with TLS 1.0 - all systems required 21 77
Adding VPN user with Cisco RV110W changes IP address 7 26
local DNS vendor. 4 12
Article by: btan
Provide an easy one stop to quickly get the relevant information on common asked question on Ransomware in Expert Exchange.
An analysis of the phishing scam that has been affecting Google users, along with steps to take for protection, as well as what to do if you receive one of the emails.
Sending a Secure fax is easy with eFax Corporate (http://www.enterprise.efax.com). First, Just open a new email message.  In the To field, type your recipient's fax number @efaxsend.com. You can even send a secure international fax — just include t…
Both in life and business – not all partnerships are created equal. Spend 30 short minutes with us to learn:   • Key questions to ask when considering a partnership to accelerate your business into the cloud • Pitfalls and mistakes other partners…

867 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question

Need Help in Real-Time?

Connect with top rated Experts

18 Experts available now in Live!

Get 1:1 Help Now