Re: DMZ design
Available news archives: comp.lang.tcl - comp.lang.python - comp.security.firewalls - sci.crypt - comp.lang.php - comp.lang.javascript
Google
 
Web news.hping.org


comp.security.firewalls archive

Re: DMZ design

From: Ansgar -59cobalt- Wiechers <usenet-2005@planetcobalt.net>
Date: Thu Dec 01 2005 - 11:27:47 CET

Leythos wrote:
> In article <3v6choF13kt77U1@individual.net>, usenet-2005@planetcobalt.net says...
>> Leythos wrote:
>>> lets take an online ordering system, or a project management system
>>> or anything else that doesn't use a Static DB, and then you either
>>> punch a hole or setup replication, so you're back to having a
>>> security issue that you have to deal with one way or another.
>>
>> As I said: even if I use (live-)replication, I'm not likely to be
>> vulnerable to the same exploit. And even if I were: my exposure would
>> be *at most* as high as it were in your scenario.
>
> So, we're on the same page and just not seeing it. If the exposure is
> the same for real-time access, then it's not worth doing it with
> multiple DMZ's.

Do you read only every other word or something? The exposure is AT MOST
the same. In general it is LOWER. So using multiple DMZs IS worth the
effort.

cu
59cobalt

-- 
"Another option [for defragmentation] is to back up your important files,
erase the hard disk, then reinstall Mac OS X and your backed up files."
--http://docs.info.apple.com/article.html?artnum=25668
Received on Sat Dec 3 04:19:02 2005