Windows Vista Tips

Windows Vista Tips > Newsgroups > Windows Server > Server Networking > Public IPs for servers in DMZ or just good old NAT

Reply
Thread Tools Display Modes

Public IPs for servers in DMZ or just good old NAT

 
 
Thomas Moeller Nexoe
Guest
Posts: n/a

 
      01-07-2010

Hi.

We are about to make some changes to our network setup and I have been
put in charge of compiling some documentation on how to best setup our
new network environment.

We will be using a Cisco firewall box and a 3-leg perimeter network
setup with ISA server. So far so good.

I have been administering a similar setup in my previous job where we
used to go for public ip addresses for the public accessible servers in
the ISA DMZ - my opinion is that the pubic ip address scheme gives
easier administration in both the Cisco and in the ISA server in terms
of rules and troubleshooting, but I can't seem to convince my boss about
this. He wants to go for a single public ip address and then use NAT for
the servers. I.E. Translate requests based on ports and forward to the
appropriate servers on the network.

I have heard that the NAT solution provides a slightly more secure setup
because the 'outside' cannot see or know the actual servers ip adress on
the network, but are the advantage of using the NAT solution big enough
versus the easier administration with the public ip address scheme?

I mean. We have a Cisco hardware box and an ISA server 2006 between our
DMZ and the Internet.

Thanks in advance for any input!

--
Best regards,

Thomas Moeller Nexoe
--------------------------------------
Website: http://www.winfrastructure.dk
Blog: http://www.winfrastructure.net
 
Reply With Quote
 
 
 
 
Thomas Moeller Nexoe
Guest
Posts: n/a

 
      01-08-2010
On 07-01-2010 08:33, Thomas Moeller Nexoe wrote:
> Hi.
>
> We are about to make some changes to our network setup and I have been
> put in charge of compiling some documentation on how to best setup our
> new network environment.
>
> We will be using a Cisco firewall box and a 3-leg perimeter network
> setup with ISA server. So far so good.
>
> I have been administering a similar setup in my previous job where we
> used to go for public ip addresses for the public accessible servers in
> the ISA DMZ - my opinion is that the pubic ip address scheme gives
> easier administration in both the Cisco and in the ISA server in terms
> of rules and troubleshooting, but I can't seem to convince my boss about
> this. He wants to go for a single public ip address and then use NAT for
> the servers. I.E. Translate requests based on ports and forward to the
> appropriate servers on the network.
>
> I have heard that the NAT solution provides a slightly more secure setup
> because the 'outside' cannot see or know the actual servers ip adress on
> the network, but are the advantage of using the NAT solution big enough
> versus the easier administration with the public ip address scheme?
>
> I mean. We have a Cisco hardware box and an ISA server 2006 between our
> DMZ and the Internet.
>
> Thanks in advance for any input!
>

Any thoughts at all?

--
Best regards,

Thomas Moeller Nexoe
--------------------------------------
Website: http://www.winfrastructure.dk
Blog: http://www.winfrastructure.net
 
Reply With Quote
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are Off


Similar Threads
Thread Thread Starter Forum Replies Last Post
SBS 2008 - Exchange 2007 Transport Rules to BCc mail to a mail Enabled Public Folder Jim Windows Small Business Server 5 05-04-2010 02:21 PM
Re: New SBS 2003 with missing public folders Russ Grover [SBS-MVP] Windows Small Business Server 2 03-03-2010 01:36 AM
Re: MSFT Connect Officially Rejects Public Access to Bugs Chad Harris Windows Vista Installation 5 09-10-2006 04:40 AM
MSFT Connect Officially Rejects Public Access to Bugs Chad Harris Windows Vista Installation 0 09-08-2006 05:36 PM
Reporting Bugs by Public is as effective Yellin' at the TV! Chad Harris Windows Vista Installation 0 07-29-2006 01:30 AM



1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 38 39 40 41 42 43 44 45 46 47 48 49 50 51 52 53 54 55 56 57 58 59