Dmz Network; Configuring A Dmz Connection - McAfee SG310 Administration Manual

Utm firewall
Table of Contents

Advertisement

Network Setup menu options

DMZ network

Figure 80 HA connections
Repeat this procedure for the secondary appliance.
11
DMZ network
A DMZ (de-militarized zone) is a physically separate LAN segment, typically used to host servers that are
publicly accessible from the Internet. Servers on this segment are isolated to provide better security for
your LAN. If an attacker compromises a server on the LAN, then the attacker immediately has direct access
to your LAN. However, if an attacker compromises a server in a DMZ, they are only able to access other
machines on the DMZ.
Note:
DMZ is not available on the SG310 or SG640 PCI appliances.
By default, the UTM Firewall appliance blocks network traffic originating from the DMZ from entering the
LAN. Additionally, any network traffic originating from the Internet is blocked from entering the DMZ and
must be specifically allowed before the servers become publicly accessible. However, network traffic
originating from the LAN is allowed into the DMZ and network traffic originating from the DMZ is allowed
out to the Internet.
The topic
Services on the DMZ network
DMZ. To allow public access to the servers in the DMZ from the Internet, this step must be performed. You
can also allow certain network traffic originating from the DMZ into the LAN; however, this is not usually
necessary.
By default, the UTM Firewall configuration expects machines on the DMZ network to have addresses in a
private IP address range; for example, 192.168.1.0 / 255.255.255.0 or 10.1.0.0 / 255.255.0.0. Real world
addresses can be used on the DMZ network by clearing the Enable NAT from DMZ interfaces to
Internet interfaces checkbox under the Advanced tab, which enables routing to the DMZ public
addresses. You also need to ensure that upstream routers are aware of this routing configuration, typically
by communicating with your ISP. For further information, see NAT.

Configuring a DMZ connection

From the Network Setup menu, select Network Setup > Connections. The Connections page
1
appears.
For the network port being connected to the DMZ, select Direct Connection from the Change Type list.
2
The Direct Connection Settings page appears
80
McAfee UTM Firewall 4.0.4 Administration Guide
discusses how to allow certain traffic from the Internet into the
(Figure
81).

Hide quick links:

Advertisement

Table of Contents
loading

This manual is also suitable for:

Sg560Sg560uSg565Sg580

Table of Contents