Compare cert salaries and plan your next career move
apr911 wrote: » Is it a business requirement to use a two tiered firewall setup? From the sounds of the configuration you want its not, because if the 2nd tier firewall fails you still want it to pass traffic as if it doesnt exist. So why dont you just configure the redundant firewalls with 2 segments?
it_consultant wrote: » The security advantage to having back to back firewalls is basically nill. I think this is right on track, get a pair of highly available firewalls and set up a network zone for your DMZ.
Trifidw wrote: » How many interfaces does your internet firewall have? If it is 3 or more (excluding any that are used for redundancy) than why not just hang the DMZ off those?
onesaint wrote: » Another vote for this methodology. I'm not sure 1. why you would want to shut the firewall off, and 2. why you would want to place a cheap ready to fail firewall in front of your internal zone. Is this a design requirement?
Mishra wrote: » This is actually what we do currently. We are interested in adding an internal firewall behind our perimeter that is of a different vendor. Gives us 2 advantages. If a vulnerability is exposed in the perimeter, hopefully a having a different vendor's firewall behind will stop this. Other advantage if the perimeter firewall is compromised, we will have another firewall behind. If we continue to setup the multi-legged firewall approach, then if the firewall is compromised we have no ability to block that traffic. The intruder would be able to setup anything they like to attack/steal our customer data. This reply was for most people's posts here. Thanks for commenting!
networker050184 wrote: » I've seen a few devices that can continue to "forward" traffic while the device is off. Its not actually forwarding anything though, its a physical switch that connects two ports as if it were a single wire. Most devices I've seen this on are taps that sit in the wire anyway. Never seen a firewall with this feature, but that doesn't mean one doesn't exist.
Mishra wrote: » Right, exactly. Do you know what device that does this?
Compare salaries for top cybersecurity certifications. Free download for TechExams community.