25.02.2013 Views

TCP/IP Tutorial and Technical Overview - IBM Redbooks

TCP/IP Tutorial and Technical Overview - IBM Redbooks

TCP/IP Tutorial and Technical Overview - IBM Redbooks

SHOW MORE
SHOW LESS

Create successful ePaper yourself

Turn your PDF publications into a flip-book with our unique Google optimized e-Paper software.

Internal<br />

DNS <strong>and</strong><br />

Mail server<br />

Secure network<br />

organization.com<br />

Client1 Client2<br />

Figure 22-21 Screened host firewall<br />

This configuration allows an information server to be placed between the router<br />

<strong>and</strong> the bastion host. Again, the security policy determines whether the<br />

information server will be accessed directly by either outside users or internal<br />

users, or if it will be accessed through the bastion host. If strong security is<br />

needed, traffic from both the internal network to the information server <strong>and</strong> from<br />

outside to the information server can go through the bastion host.<br />

In this configuration, the bastion host can be a st<strong>and</strong>ard host or, if a more secure<br />

firewall system is needed, it can be a dual-homed host. In this case, all internal<br />

traffic to the information server <strong>and</strong> to the outside through the router is<br />

automatically forced to pass the proxy server on the dual-homed host. The<br />

bastion host is then the only system that can be accessed from the outside. No<br />

one should be permitted to log on to the bastion host; otherwise, an intruder<br />

might log on the system <strong>and</strong> change the configuration to bypass the firewall.<br />

Screened subnet firewall (demilitarized zone)<br />

This type of firewall consists of two packet-filtering routers <strong>and</strong> a bastion host.<br />

Screened subnet firewalls provide the highest level security among the different<br />

firewall types (see Figure 22-22 on page 809). This is achieved by creating a<br />

808 <strong>TCP</strong>/<strong>IP</strong> <strong>Tutorial</strong> <strong>and</strong> <strong>Technical</strong> <strong>Overview</strong><br />

Bastion host gateway<br />

Proxy<br />

servers<br />

Packet<br />

filter<br />

SOCKS<br />

server<br />

External<br />

DNS<br />

Public<br />

server<br />

Untrusted network<br />

WWW<br />

FTP<br />

Internet<br />

Router<br />

Packet<br />

filter

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!