no, I'm saying exposing windows to the internet is always a bad idea. 
it should NEVER be in a dmz, and should always be protected by the 
firewall with a policy reject or policy drop.

Simon Hobson wrote:
> Christ Schlacta wrote:
>> In general you should never have a windows machine in a dmz.Thats the
>> biggest problem with this setup
> 
> Well if you are exposing it to the outside world then that's exactly 
> where it should be. I agree that if it's not accessible from outside, 
> it shouldn't be there. It wasn't clear from the original question if 
> this was publicly visible machine.
> 
> In our case, it wasn't a DMZ but a management VLAN to which the 
> customers didn't have access.

------------------------------------------------------------------------------
Let Crystal Reports handle the reporting - Free Crystal Reports 2008 30-Day 
trial. Simplify your report design, integration and deployment - and focus on 
what you do best, core application coding. Discover what's new with 
Crystal Reports now.  http://p.sf.net/sfu/bobj-july
_______________________________________________
Shorewall-users mailing list
[email protected]
https://lists.sourceforge.net/lists/listinfo/shorewall-users

Reply via email to