Should a router be placed between the firewall and DMZ?
Modern firewalls have the ability to serve as a router, negating the need of another device on a network. There are exceptions to this router rule, however. Network security expert Mike Chapple explains.
It's more likely that you'll need a router between your firewall and the Internet. In this location, a router can screen out an Internet stream's obvious "junk traffic" before it reaches the firewall. You can use the router to apply broad firewall rules across the enterprise. For example, if you don't allow any SSH traffic through the firewall, you can drop all inbound port 22 traffic at the router, letting the firewall focus on arbitrating tougher decisions.
Some firewalls do act as proxy servers, but only if they are specifically designed as Layer 7, or application-layer firewalls. Consider the case where an internal user wishes to access an external Web site. The proxy firewall transparently inserts itself into the conversation, completing the three-way handshake with the end user, determining whether the traffic is allowed, and then completing a separate three-way handshake with the destination system.
- Learn how to conduct firewall configuration reviews.
- Discover the different ways to place systems in a network topology.
Dig Deeper on Network security
Related Q&A from Mike Chapple
Stateful vs. stateless firewalls: Understanding the differences
Examine the important differences between stateful and stateless firewalls, and learn when each type of firewall should be used in an enterprise ... Continue Reading
Wired vs. wireless network security: Best practices
Explore the differences between wired and wireless network security, and read up on best practices to ensure security with or without wires. Continue Reading
The difference between AES and DES encryption
Choosing to encrypt confidential data with AES or DES encryption is an important cybersecurity matter. Learn about the important differences between ... Continue Reading