22.12.2012 Views

Front cover - IBM Redbooks

Front cover - IBM Redbooks

Front cover - IBM Redbooks

SHOW MORE
SHOW LESS

Create successful ePaper yourself

Turn your PDF publications into a flip-book with our unique Google optimized e-Paper software.

148 Lotus Security Handbook<br />

One final point regarding Figure 4-8: the firewalls and depicted connections are<br />

not meant to imply that one zone cannot connect to another non-adjacent zone.<br />

For example, a workstation in the Intranet zone is going to be permitted in our<br />

model to connect “directly” to the Internet zone (or the Proxy zone). It does show,<br />

however, that this type of connection will need to traverse multiple firewall<br />

routers.<br />

Now that we have shown the logical inter-zone connections and firewalls, we can<br />

put this together with our physical representation of the firewall routers to depict<br />

the physical inter-zone connections. We only show the physical router<br />

connections; a more detailed physical diagram would include the switches and<br />

hubs used for the actual NIC connections. In Figure 4-9, we show a single series<br />

of routers. In actual practice, redundant firewall routers would be preferred as this<br />

is a widely accepted best practice.<br />

ISP router<br />

Firewall (filtering router)<br />

Firewall (filtering router)<br />

Firewall (filtering router)<br />

Proxy Zone<br />

Host<br />

Public IP<br />

Public-facing IP<br />

Proxy Zone<br />

Host<br />

Data Access 1 IP<br />

Data Access Zone 1<br />

Data Access<br />

Zone Host<br />

Proxy Zone IP<br />

Data Access<br />

Zone Host<br />

Intranet IP<br />

Internet Zone<br />

Proxy Zone<br />

Host<br />

Data Access Zone 2<br />

Data Access<br />

Zone Host<br />

Figure 4-9 Firewall physical separation of Inter-zone communications<br />

Proxy Zone<br />

Data Access 2 IP<br />

Intranet Zone<br />

In this figure, the number of firewalls with filtering routers was arbitrarily selected.<br />

And remember from our firewall descriptions earlier, the “firewall router” may<br />

consist of more than one physical box. The important point is that all connection<br />

paths between any two adjacent zones must go through a firewall so we can

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!