Yes there are.
You don't want to have one machine crashing your whole domain.
Regarding 2 firewalls is serie, lets just say that a hacker breaking in who
encounters a 2nd firewall will use the same technique on the 2nd one. When
that doesn't work, you have more time to take appropriate actions.
Hope this helps.
Cheers,
Marc
----- Original Message -----
From: "Ivan Fox" <[EMAIL PROTECTED]>
To: "fw-wiz" <[EMAIL PROTECTED]>; "fw-1-mailinglist (e-mail)"
<[EMAIL PROTECTED]>
Sent: Saturday, January 13, 2001 2:29 PM
Subject: [FW1] Best Practice?!
>
> Are the following two items "best practices"? Your comments are
> appreciated.
>
> 1) All NT-based servers in a DMZ should be stand-alone servers, not member
> servers of a NT Domain?
>
> 2) If two firewalls in serial, they should be of different make, for
> instance, Check Point on NT and Check Point on Solaris or Check Point and
> PIX?!
>
>
>
>
>
============================================================================
====
> To unsubscribe from this mailing list, please see the instructions at
> http://www.checkpoint.com/services/mailing.html
>
============================================================================
====
>
================================================================================
To unsubscribe from this mailing list, please see the instructions at
http://www.checkpoint.com/services/mailing.html
================================================================================