cyberspace
Technical User
Where I work there is a 2mbit leased line and we have a /27 public subnet giving us 30 public IP addresses. The router (little ISP owned Cisco) is x.x.x.129, firewall .130. On here we have our mail server, VPN termination point, web sites, etc. This is used for some internet access but users are routed via an ADSL connection.
The existing firewall is a Symantec Raptor, old stuff, works quite well but it's heavily outdated and running on an old PC.
The DMZ isn't really a proper DMZ...what happens is:
Internet --> x.x.x.129 --> 8 port switch which has DMZ hosts coming off it --> x.x.x.130 --> LAN
Not the ideal setup (I believe this is called a "blow hole" as opposed to a proper DMZ?) but it works and the Raptor does apply rules to the hosts coming off the switch.
We recently purchased a 3Com X506, which is a "Unified Threat Management System" and it's got plenty of features. However, in testing, setting up the DMZ in the same way just didn't work and no rules were applied. I could set up a security zone for the DMZ, but then I'm not sure how that would work for our range of public addresses.
It's leaving me rather stumped right now, so any suggestions would be welcomed!
'When all else fails.......read the manual'
The existing firewall is a Symantec Raptor, old stuff, works quite well but it's heavily outdated and running on an old PC.
The DMZ isn't really a proper DMZ...what happens is:
Internet --> x.x.x.129 --> 8 port switch which has DMZ hosts coming off it --> x.x.x.130 --> LAN
Not the ideal setup (I believe this is called a "blow hole" as opposed to a proper DMZ?) but it works and the Raptor does apply rules to the hosts coming off the switch.
We recently purchased a 3Com X506, which is a "Unified Threat Management System" and it's got plenty of features. However, in testing, setting up the DMZ in the same way just didn't work and no rules were applied. I could set up a security zone for the DMZ, but then I'm not sure how that would work for our range of public addresses.
It's leaving me rather stumped right now, so any suggestions would be welcomed!
'When all else fails.......read the manual'