We currently use a Cisco PIX firewall device for our firewall and NAT router, although pretty much any firewall device will suffice including another server acting as a firewall. We then block all ports by default and then "punch holes" through for services like ftp, web, email, with NAT redirects to the correct internal IP of the corresponding server.
I think this would be considered a safer setup than putting the servers in a DMZ zone as the entire range of ports on the server are open to potential attacks.
Code:
((Internet)) --> [Firewall/Router] <-- Port 21/ftp ---> [FTP Server]
^---- Port 80/http --> [Web Server]
Recent comments
8 hours 37 min ago
13 hours 36 min ago
15 hours 2 min ago
15 hours 56 min ago
17 hours 39 min ago
22 hours 2 min ago
22 hours 54 min ago
1 day 1 hour ago
1 day 14 hours ago
1 day 15 hours ago