Confused??

I am trying to understand how security is set up on networks but cant seem to paint a picture in my mind of how it works. I`ll explain.... To have a RRAS server OUTSIDE your interior network means that the RRAS server is not joined to your Domain ( is this right?) sounds right!! but then where would a Firewall go if you wanted it between your RRAS server and interior network??? Does it go on the RRas server side or Interior network side or does`nt it matter????? As you can see i`m struggling. But soooo determined to understand.
Comments
So, to better summarize this, the fireware is what separates the two networks (but is connected to both). The firewall can, but doesn't need to be part of an active directory domain.
Take Care,
Rcoop
Internet --- Firewall --- DMZ (w/RRAS) --- Firewall --- Internal Network
Other security considerations can come into play such as the aforementioned VPN, a VPN concentrator, the RRAS being "hardened" (Bastion Host concept), etc. Whether or not the RRAS is a member of the domain (applies to Windows environments) is debatable for several reasons and also depends on what firewall you use.
I hope this post has helped!
This forum is the best!!!!