Firewall Implimentation - Recomendations


 
Thread Tools Search this Thread
Special Forums Cybersecurity Firewall Implimentation - Recomendations
# 8  
Old 09-22-2006
HERE is an IDea of what our serve room looks like. as far as the server racks and the switch racks go. There is more to the room, and more stuff in it but this is the stuff we are talking about. The Modem is T-1 that is our only signal coming into the building for Internet.

DAMN i created the file but i can not insert the image, it is not hosted anywhere. I am going to send it to your Forum box, assuming i can, so you can see what i am working with.

When you get it, you will see our rack. What i would LIKE to do is in the rack put 1 or 2 for redundancy, OpenBSD servers in there, to run the firewalls. Now these will be Xeons with like a gig of RAM so i would almost use them for more than just firewall purposes, but that is just a possibility, i am sure we can get a low end server for this purpose. ALL of our Servers are DELL or worse... (Supermicro). I am encouraging my company to switch to IBM servers or something else. Either way, i will try to send you the file so you can see what we have NOW, and that will help define possible advice for this project.

Sending now.
# 9  
Old 09-22-2006
Apparetly i can not send you a message... SO i will try and see about getting the imagine hosted or something by 12:30.
# 10  
Old 09-22-2006
Here we go. Hosted the picture on Yahoo.

Image

The image itself kind of sucks, i was trying to save space and not take too long as well. Either way it kind of illustrates our problem :-P

As i said, most of the Racks are Dell 1850 - 1U, Dell 2850 - 2U, Dell 6500 6U.

total of 6 Nortel Baystack switches (48 port) 2 nortel Baystack switches (24 ports). All at the top on the switch rack is just our patch panels. They plug directly into the 2 network switches starting form top to bottom.

If you think this is bad, you should have seen it before my bosses started to clean it all up.
# 11  
Old 09-22-2006
Quote:
Originally Posted by pathological
... What i would LIKE to do is in the rack put 1 or 2 for redundancy, OpenBSD servers in there, to run the firewalls. Now these will be Xeons with like a gig of RAM so i would almost use them for more than just firewall purposes, but that is just a possibility, i am sure we can get a low end server for this purpose ...
I would advise against using your firewall boxes for anything other than firewalling. The more services you run on a box, the more vulnerable it becomes. Your firewalls should be rock solid bastions of defence. As for your rack config, the physical layout of your boxes in the rack isn't really the issue*, it's the logical configuration you should be more concerned with. Don't just focus on your firewalls, take a layered approach to security models and think about all of the traffic, services, users and data that your systems involve.

I can't view the image you posted. I use ImageShack to host images for stuff like this forum, check it out. Post a visio diagram of your network layout (**NO real external IPs/Addresses or other company identifying information!!**) if you can ...

* I won't go into UPS, power & cooling considerations for now.
# 12  
Old 09-22-2006
I would never post that sort of info ;-) As for cooling, no worries, we had a special AC unit installed for the room, it is currently sitting at 71F right now :-) And as for backup power, we have a HUGE mother of a battery. The whole room is on it, it has enough charge to last for over an hour. Bout an hour and a half i think it is.

Rack Image

I can not get the image to embed in the into the post but the link to it is now above.
Login or Register to Ask a Question

Previous Thread | Next Thread

9 More Discussions You Might Find Interesting

1. Cybersecurity

Firewall

Hey Guys, I am looking for a good firewall software to implement in medium/large office, with at least 150 users. I was hopping you guys could help me on this one. Regards, (4 Replies)
Discussion started by: andrevicente
4 Replies

2. Linux

Firewall?

Dear All I have put my windows machine behind my centos firewall server with just one NIC. At now, the windows machine can ping 192.9.9.3 but cannot resolve valid url (like www.google.com). I have set DNS for it as well. Can you please let me know what is the missing step? Thank you (6 Replies)
Discussion started by: hadimotamedi
6 Replies

3. SuSE

Firewall

Is there a command line interface to the firewall? (4 Replies)
Discussion started by: jgt
4 Replies

4. AIX

Firewall

:b:Hi,, How do configure firewall in aix.. similar to linux iptable. Rgards, k.sumathi. (3 Replies)
Discussion started by: sumathi.k
3 Replies

5. Cybersecurity

help with firewall

hi everyone I am a newbee to firewall scripting. cannot understand how to write rules per host. in ip6tables. anyone plz:( (2 Replies)
Discussion started by: xecutioner
2 Replies

6. Shell Programming and Scripting

crone job implimentation

I wanted to enable one shell script in the cronetab,how to do crone tabe enabling pl help me:( regards, ramesh (1 Reply)
Discussion started by: Ramesh Vellanki
1 Replies

7. UNIX for Dummies Questions & Answers

Firewall Box

I am a novice to linux and unix and command line, I am willing to jump in head first. I have a couple older computers, one is a dell XPS with a P2 Proccessor and th other is a old old sony VIAO. I have a small home network 3 computers...i have my DSL modem then thats connected to my wireless... (2 Replies)
Discussion started by: Tabryan07
2 Replies

8. Cybersecurity

Looking Out from Behind a Firewall

Would it be possible to restrict access to internet pages in the following way? A machine: IP = 128.1.17.123 Only pages from domains of the type "go.jp" and "ne.jp" are viewable. All others are not viewable or only partly viewable. B machine: IP = 128.1.17.146 Regardless of the domain... (4 Replies)
Discussion started by: mntamago
4 Replies

9. Cybersecurity

What Firewall do you use?

Just out of curiosity, I see a lot of people here use Linux IPTables as their firewall. Anyone here use something else like OpenBSD PF or *BSD IPF, IPFW? I'm quite fond of OpenBSD and their Packet Filters. I find their syntax much easier to manage and from my personal experience, I find them... (5 Replies)
Discussion started by: tarballed
5 Replies
Login or Register to Ask a Question