Please help - VPN and DMZ question

Please help - VPN and DMZ question

Secure Home | Search | About
 Networking Firewalls    Post an article   get this group's latest topics as an RSS feed add this group's latest topics to your My MSN content add this group's latest topics to your My Yahoo content add this group's latest topics to your Google content
Subject Author Date
Please help - VPN and DMZ question aether8203 04-19-2005
Posted by on April 19, 2005, 2:41 pm
If you were  Registered and logged in, you could reply and use other advanced thread options
We are trying to establish a VPN from a small office back to the
corporate intranet. For the small office we have a simple PIX firewall
and for the corporate side, we have a Sidewinder (3 "burbs": external,
internal, DMZ).

My idea is to put a PIX firewall in the DMZ and the distant small
office will have an encrypted tunnel between PIX to PIX. But then I
would have to pop a HUGE hole in the Sidewinder to allow traffic back
into the internal area. Isn't a DMZ not supposed to have traffic into
an internal area? Isn't that the point of a DMZ? Traffic stays out of
the internal network but internal can still get to the DMZ?

Would it be better if I made the Sidewinder just be one of the "ends"
of the VPN? So I would have PIX to Sidewinder?

Any information on that type of configuration?

Thanks!



Posted by Leythos on April 19, 2005, 9:54 pm
If you were  Registered and logged in, you could reply and use other advanced thread options
On Tue, 19 Apr 2005 14:41:24 -0700, aether8203 wrote:

> We are trying to establish a VPN from a small office back to the
> corporate intranet. For the small office we have a simple PIX firewall
> and for the corporate side, we have a Sidewinder (3 "burbs": external,
> internal, DMZ).
>
> My idea is to put a PIX firewall in the DMZ and the distant small office
> will have an encrypted tunnel between PIX to PIX. But then I would have
> to pop a HUGE hole in the Sidewinder to allow traffic back into the
> internal area. Isn't a DMZ not supposed to have traffic into an
> internal area? Isn't that the point of a DMZ? Traffic stays out of the
> internal network but internal can still get to the DMZ?
>
> Would it be better if I made the Sidewinder just be one of the "ends" of
> the VPN? So I would have PIX to Sidewinder?
>
> Any information on that type of configuration?

I don't have a sidewinder, but if you can't do a site to site VPN then you
need to get a different firewall. You should be able to setup a PIX to
Sidewinder IPSec tunnel, then create rules that allow/deny access from
each side to the other.


--
spam999free@rrohio.com
remove 999 in order to email me



Similar ThreadsPosted
NIS Pro '03 Question. November 15, 2004, 3:11 pm
dmz question April 16, 2005, 4:15 pm
A question regarding bg4.exe April 21, 2005, 9:34 am
NAT question July 27, 2005, 9:06 am
NAT Question October 19, 2005, 10:58 am
Question About DMZ October 21, 2005, 7:41 pm
Re: PIX vpn question June 20, 2006, 7:26 pm
Question about dummy.exe July 28, 2004, 1:51 am
Smoothwall question January 28, 2005, 5:33 pm
NetScreen NAT/VPN question April 22, 2005, 12:18 pm

The site map in XML format XML site map

Contact Us | Privacy Policy