Sent: 03/12/2008
From: Ian
Message:need to build a system with a virtual DMZ: Internet -- primary firewall --
Servers in DMZ area -- sencondary firewall -- LAN, all on the same VS
machine. I have finished the LAN part so far. I guess it can be done by using
MS ISA as firewall, isn't it? Is there other way to do it ? Thanks.
"Bill Grant" wrote:
Show quoted text
> What environment? - in this virtual network on the VS machine
>
> Building a DMZ is no different just because because some or all of the
> networks are virtual networks. The same rules apply.
>
> Where did you plan to put the DMZ? What type of DMZ do you plan to use?
> What are you planning to use for firewall(s)?
>
> "Ian" <(email address - cut out)> wrote in message
> news:(email address - cut out)...
> > Is there a way to build a DMZ inside this VS envirenment? I have built a
> > system with a domain and 8 servers. Thanks.
>
>
Sent: 03/12/2008
From: "Bill Grant" <not.available@online>
Message: What environment?
Building a DMZ is no different just because because some or all of the
networks are virtual networks. The same rules apply.
Where did you plan to put the DMZ? What type of DMZ do you plan to use?
What are you planning to use for firewall(s)?
"Ian" <(email address - cut out)> wrote in message
news:(email address - cut out)...
Show quoted text
> Is there a way to build a DMZ inside this VS envirenment? I have built a
> system with a domain and 8 servers. Thanks.
Sent: 03/12/2008
From: "Lefty" <(email address - cut out)>
Message:You have some options... you COULD use RRAS and handle routing that way...
it will ask you what network interface is public/internet facing and then
setup rules on your response... I personally recommend ISA2006 for this..
same thing... install isa2006 and then choose the three-legged firewall...
this then creates default rules/policies based on your requirments... i
like to name my interfaces sometihng that makes sense (to me)
RED (internet facing)
ORANGE (DMZ)
BLUE (Wireless)
GREEN (Production)
i have a physical machine with 4 nics setup just this way... have also done
3 nic setups in Virtual Server the sme way... you just give your RED
interface access to the internet or the LAN that you want it to talk to...
the other virtual network cards talk to virtual switches...
r
"Ian" <(email address - cut out)> wrote in message
news:(email address - cut out)...
Show quoted text
> need to build a system with a virtual DMZ: Internet -- primary firewall --
> Servers in DMZ area -- sencondary firewall -- LAN, all on the same VS
> machine. I have finished the LAN part so far. I guess it can be done by
> using
> MS ISA as firewall, isn't it? Is there other way to do it ? Thanks.
>
>
>
> "Bill Grant" wrote:
>
>> What environment? - in this virtual network on the VS machine
>>
>> Building a DMZ is no different just because because some or all of
>> the
>> networks are virtual networks. The same rules apply.
>>
>> Where did you plan to put the DMZ? What type of DMZ do you plan to
>> use?
>> What are you planning to use for firewall(s)?
>>
>> "Ian" <(email address - cut out)> wrote in message
>> news:(email address - cut out)...
>> > Is there a way to build a DMZ inside this VS envirenment? I have built
>> > a
>> > system with a domain and 8 servers. Thanks.
>>
>>