Hi
You'll need a proxy/rev-proxy device in the DMZ. I use
Sun Iplanet Web proxy. One thing you might consider is
to create another subnet similar to what you've done
for the DMZ and use it for external (Non-NAT)
services. This is where you would put your
proxy/rev-proxy device. This "non-NAT'ed" subnet I
actually call a "DMZ" and the NAT'ed subnet a
"Service" net. The architecture looks like this:
|-----DMZ (Non-NAT'ed)
|
internet----[router]-------[fw-ng]--------LAN
|
|-----Service (NAT'ed)
In the above architecture, the proxy would be in the
DMZ.
--- Naseer Inamdar <[EMAIL PROTECTED]>
wrote:
> Hi all,
>
> As per our network policy, nobody should access the
> servers on the LAN from
> INTERNET directly. We have two checkpoint firewalls
> connected back to back
> separating DMZ zone.
>
> Internet
> |
> Router
> |
> Checkpoint firewall-1
> |
> |
> ---------------------------------------------- DMZ
> |
> Checkpoint firewall-2
> |
> |
> LAN
>
> Both checkpoint firewall have different Policies and
> are not in load
> balancing mode.The strategy is to have defense in
> depth approach. All
> Internet bound traffic terminates to protected DMZ.
> However we have few
> servers that are present on LAN, that are required
> to be accessed over
> Internet. The amount of access to these servers from
> Internet will be less
> compared to the LAN users, hence cannot be shifted
> to DMZ. What would be the
> best practice for accessing these servers. These
> users want access without
> VPN connectivity as they dont carry laptops.
>
> I have thought of the following solution:
>
> Install a reverse proxy server for eg: ISA firewall
> that hosts these
> internal servers. All access to these servers shall
> be then via ISA-
> firewall which sits on DMZ and communicates to
> these internal servers via
> Checkpoint firewall-2. through a secure channel like
> SSL.
>
> Since ISA firewall hosts multiple servers. How a
> person can access different
> servers -- for eg: server1, server-2
> Note: DMZ is on invalid ip nated to Valid IP on
> Checkpoint firewall-1
>
> Awaiting for more inputs and other best solutions
>
> Thanks and Regards
> Naseer.Inamdar
>
>
>
>
>
>
>
>
---DISCLAIMER-------------------------------------------------
> The contents of this E-mail (including the contents
> of the
> enclosure/(s) or attachment/(s) if any) are
> privileged and
> confidential material of Mahindra and Mahindra
> Limited (M&M)
> and should not be disclosed to, used by or copied in
> any
> manner by anyone other than the intended
> addressee/(s). If
> this E-mail (including the enclosure/(s) or
> attachment/(s)
> if any ) has been received in error, please advise
> the
> sender immediately and delete it from your system.
> The views
> expressed in this E-mail message (including the
> enclosure/(s)
> or attachment/(s) if any) are those of the
> individual sender.
>
--------------------------------------------------------------
>
> =================================================
> To set vacation, Out-Of-Office, or away messages,
> send an email to [EMAIL PROTECTED]
> in the BODY of the email add:
> set fw-1-mailinglist nomail
> =================================================
> To unsubscribe from this mailing list,
> please see the instructions at
> http://www.checkpoint.com/services/mailing.html
> =================================================
> If you have any questions on how to change your
> subscription options, email
> [EMAIL PROTECTED]
> =================================================
>
__________________________________________________
Do You Yahoo!?
Tired of spam? Yahoo! Mail has the best spam protection around
http://mail.yahoo.com
=================================================
To set vacation, Out-Of-Office, or away messages,
send an email to [EMAIL PROTECTED]
in the BODY of the email add:
set fw-1-mailinglist nomail
=================================================
To unsubscribe from this mailing list,
please see the instructions at
http://www.checkpoint.com/services/mailing.html
=================================================
If you have any questions on how to change your
subscription options, email
[EMAIL PROTECTED]
=================================================