Networking Forums

Networking Forums > Computer Networking > Windows Networking > Dual NIC Card - Question

Reply
Thread Tools Display Modes

Dual NIC Card - Question

 
 
Bluehades
Guest
Posts: n/a

 
      10-19-2005, 06:42 PM
Hello's,
I'm in the process of setting up a seperate Backup Traffic LAN. I have
installed a 2nd NIC on each of my servers for backup traffic.
I have a security concern. Some of the servers are in the DMZ. Does the 2nd
NIC pose a security risk where traffic could move from one NIC onto the 2nd
NIC? How do you prevent traffic from being routed between the 2 NIC's? I have
Win2k & Win 2003 servers.

Many thanks for your time.

Blue.
 
Reply With Quote
 
 
 
 
Neteng
Guest
Posts: n/a

 
      10-19-2005, 07:21 PM
Yes there is a security hole there. Traffic will not route from NIC to NIC
(assuming you don't have routing on), however you've compromised your
internal network by connecting it via the 2nd NIC to your DMZ network. You
could put a firewall in between your DMZ and the internal network and adjust
your route table in the servers.

"Bluehades" <(E-Mail Removed)> wrote in message
news:6A600869-7D76-49FB-AC39-(E-Mail Removed)...
> Hello's,
> I'm in the process of setting up a seperate Backup Traffic LAN. I have
> installed a 2nd NIC on each of my servers for backup traffic.
> I have a security concern. Some of the servers are in the DMZ. Does the

2nd
> NIC pose a security risk where traffic could move from one NIC onto the

2nd
> NIC? How do you prevent traffic from being routed between the 2 NIC's? I

have
> Win2k & Win 2003 servers.
>
> Many thanks for your time.
>
> Blue.



 
Reply With Quote
 
Bluehades
Guest
Posts: n/a

 
      10-20-2005, 02:16 PM
I guess the question then is how do you prevent routing between 2 NIC's on
win2k & win2003 servers? I seem to remember in NT4 a checkbox that could
enable or disable routing between the NICs.
Any ideas?

A.

"Neteng" wrote:

> Yes there is a security hole there. Traffic will not route from NIC to NIC
> (assuming you don't have routing on), however you've compromised your
> internal network by connecting it via the 2nd NIC to your DMZ network. You
> could put a firewall in between your DMZ and the internal network and adjust
> your route table in the servers.
>
> "Bluehades" <(E-Mail Removed)> wrote in message
> news:6A600869-7D76-49FB-AC39-(E-Mail Removed)...
> > Hello's,
> > I'm in the process of setting up a seperate Backup Traffic LAN. I have
> > installed a 2nd NIC on each of my servers for backup traffic.
> > I have a security concern. Some of the servers are in the DMZ. Does the

> 2nd
> > NIC pose a security risk where traffic could move from one NIC onto the

> 2nd
> > NIC? How do you prevent traffic from being routed between the 2 NIC's? I

> have
> > Win2k & Win 2003 servers.
> >
> > Many thanks for your time.
> >
> > Blue.

>
>
>

 
Reply With Quote
 
Eric Denekamp
Guest
Posts: n/a

 
      10-20-2005, 02:18 PM
Have you tried routing without anything enabled that is related to Routing
and remote access. (RRAS) if you keep this service disabled you will see
there are no packets routed through this server.

good luck,

Eric Denekamp


> I guess the question then is how do you prevent routing between 2
> NIC's on
> win2k & win2003 servers? I seem to remember in NT4 a checkbox that
> could
> enable or disable routing between the NICs.
> Any ideas?
> A.
>
> "Neteng" wrote:
>
>> Yes there is a security hole there. Traffic will not route from NIC
>> to NIC (assuming you don't have routing on), however you've
>> compromised your internal network by connecting it via the 2nd NIC to
>> your DMZ network. You could put a firewall in between your DMZ and
>> the internal network and adjust your route table in the servers.
>>
>> "Bluehades" <(E-Mail Removed)> wrote in message
>> news:6A600869-7D76-49FB-AC39-(E-Mail Removed)...
>>
>>> Hello's,
>>> I'm in the process of setting up a seperate Backup Traffic LAN. I
>>> have
>>> installed a 2nd NIC on each of my servers for backup traffic.
>>> I have a security concern. Some of the servers are in the DMZ. Does
>>> the

>> 2nd
>>
>>> NIC pose a security risk where traffic could move from one NIC onto
>>> the
>>>

>> 2nd
>>
>>> NIC? How do you prevent traffic from being routed between the 2
>>> NIC's? I
>>>

>> have
>>
>>> Win2k & Win 2003 servers.
>>>
>>> Many thanks for your time.
>>>
>>> Blue.
>>>



 
Reply With Quote
 
Bill Grant
Guest
Posts: n/a

 
      10-21-2005, 04:02 AM
If RRAS is configured, you control IP routing from there. If RRAS is not
configured (or you are using a workstation OS which doesn't support RRAS)
you control it with a registry setting in TCP/IP parameters.. It is off by
default. W2k/2k3 does not have an enable IP routing switch like NT.

Eric Denekamp wrote:
> Have you tried routing without anything enabled that is related to
> Routing and remote access. (RRAS) if you keep this service disabled
> you will see there are no packets routed through this server.
>
> good luck,
>
> Eric Denekamp
>
>
>> I guess the question then is how do you prevent routing between 2
>> NIC's on
>> win2k & win2003 servers? I seem to remember in NT4 a checkbox that
>> could
>> enable or disable routing between the NICs.
>> Any ideas?
>> A.
>>
>> "Neteng" wrote:
>>
>>> Yes there is a security hole there. Traffic will not route from NIC
>>> to NIC (assuming you don't have routing on), however you've
>>> compromised your internal network by connecting it via the 2nd NIC
>>> to your DMZ network. You could put a firewall in between your DMZ
>>> and the internal network and adjust your route table in the servers.
>>>
>>> "Bluehades" <(E-Mail Removed)> wrote in message
>>> news:6A600869-7D76-49FB-AC39-(E-Mail Removed)...
>>>
>>>> Hello's,
>>>> I'm in the process of setting up a seperate Backup Traffic LAN. I
>>>> have
>>>> installed a 2nd NIC on each of my servers for backup traffic.
>>>> I have a security concern. Some of the servers are in the DMZ. Does
>>>> the
>>> 2nd
>>>
>>>> NIC pose a security risk where traffic could move from one NIC onto
>>>> the
>>>>
>>> 2nd
>>>
>>>> NIC? How do you prevent traffic from being routed between the 2
>>>> NIC's? I
>>>>
>>> have
>>>
>>>> Win2k & Win 2003 servers.
>>>>
>>>> Many thanks for your time.
>>>>
>>>> Blue.



 
Reply With Quote
 
 
 
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are Off


Similar Threads
Thread Thread Starter Forum Replies Last Post
Dual NIC card configuration kones Windows Networking 3 01-02-2008 01:07 AM
Dual-Network Card VPN Server? JHO Windows Networking 5 08-25-2005 10:51 PM
Dual NIC Question =?Utf-8?B?bXltb2JpbGU=?= Windows Networking 1 03-22-2005 05:11 PM
hp j2585a 10 / 100 dual port ethernet card chad Linux Networking 0 10-31-2004 08:33 PM
Dual card access point configuration MatB Wireless Internet 2 03-06-2004 09:58 AM



1 2 3 4 5 6 7 8 9 10 11