Hi Eliot,

if you only have one Network Sensor than I would suggest to connect it to the
switch on the DMZ.
Otherwise you might get fired with alarms on your external network :-)
Also, if you have the posibility connect the management port of the sensor to a
separate "admin network" that is only accessible for the administrators
workstation.

Regards,
Marco




"Eliot Irons" <[EMAIL PROTECTED]> am 08.05.2001 15:15:41

An:   [EMAIL PROTECTED]
Kopie:     (Blindkopie: Marco Rossi/asap)

Thema:    [FW1] ISS Real Secure







All,

We are deploying two Checkpoint FW-1 4.1 on Solaris 2.8 with Stonebeat
fullcluster.

INTERNET > CSU/DSU > ROUTER > FW-1 > ROUTER > CORE SWITCH

                                                                         DMZ

INTERNET > CSU/DSU > ROUTER > FW-1 > ROUTER > CORE SWITCH

I am trying to find the best place behind the FWs to put a ISS Real Secure
Network Sensor. Any experience someone could share I would appreciate it.

Eliot Irons
Information Services Security
[EMAIL PROTECTED]




This e-mail is confidential.  If you are not the intended recipient, you must
not disclose or use the information contained in it.  If you have received this
mail in error, please tell us immediately by return e-mail and delete the
document.


================================================================================
     To unsubscribe from this mailing list, please see the instructions at
               http://www.checkpoint.com/services/mailing.html
================================================================================








================================================================================
     To unsubscribe from this mailing list, please see the instructions at
               http://www.checkpoint.com/services/mailing.html
================================================================================

Reply via email to