Networking Forums

Networking Forums > Computer Networking > Linux Networking > Multiple firewalls

Reply
Thread Tools Display Modes

Multiple firewalls

 
 
Tam
Guest
Posts: n/a

 
      04-19-2004, 01:50 AM
Setting up a network of load balanced HTTP servers.

My question arises in that im wondering at the benefits of having
independant firewalls on each machine.

I have 6 machines, all with two NIC's with only one machine having the
real world IP on eth0. Each has RH9 so im using iptables.

The network is setup using 192.168.0.11-16 and the firewall is set up
nicely. But what if i run a firewall on each server? Each only has to
listen on port 80 so is there any network benefits to doing this?

Im thinking here of perhaps the DNS server flooding the network on the
broadcast address... each machine would be listening to each packet.
Would this make things 'faster' at the server level?

The intention of course is the network will never be compromised but
are there any real security benefits to be gained here?

What can i be doing to make it more secure? Thanks for any light
anyone can shed on this
 
Reply With Quote
 
 
 
 
James Knott
Guest
Posts: n/a

 
      04-19-2004, 10:43 AM
Tam wrote:

> The intention of course is the network will never be compromised but
> are there any real security benefits to be gained here?
>


With security, the rule is defence in depth. The more barriers you create,
the harder it is for someone to break in.

--

Fundamentalism is fundamentally wrong.

To reply to this message, replace everything to the left of "@" with
james.knott.
 
Reply With Quote
 
chris-usenet@roaima.co.uk
Guest
Posts: n/a

 
      04-29-2004, 02:14 PM
Tam wrote:
> The intention of course is the network will never be compromised but
> are there any real security benefits to be gained here?


James Knott <(E-Mail Removed)> wrote:
> With security, the rule is defence in depth. The more barriers you create,
> the harder it is for someone to break in.


But if those barriers are all the same, then presumably if one can be
compromised then they all can. The key is "[security] in depth", which
requires that you have *different* layers of defence.

Chris
 
Reply With Quote
 
 
 
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are Off


Similar Threads
Thread Thread Starter Forum Replies Last Post
MN-700 and Firewalls Stew Partington Broadband Hardware 2 07-21-2004 04:00 AM
Any point in multiple firewalls? Michael Foggin Broadband 5 06-14-2004 09:30 PM
IPSec NATTING and multiple firewalls Bernd Broadband Hardware 0 04-01-2004 10:06 AM
ICS & Firewalls Trevor Dennis Broadband 11 09-19-2003 07:44 PM
firewalls joseph Windows Networking 0 07-02-2003 08:36 AM



1 2 3 4 5 6 7 8 9 10 11