Adding A Demilitarized Zone (Dmz); Figure 13-10 Typical Firewall Load-Balancing Topology With Dmz - Nortel Web OS Switch Software Application Manual

Switch software
Table of Contents

Advertisement

Web OS 10.0 Application Guide

Adding a Demilitarized Zone (DMZ)

Implementing a DMZ in conjunction with firewall load balancing enables the Web switch to
do the traffic filtering, off-loading this task from the firewall. A DMZ is created by configuring
FWLB with another real server group and a redirection filter towards the DMZ subnets.
The DMZ servers can be connected to the Web switch on the dirty side of the firewall. A typi-
cal firewall load balancing configuration with a DMZ is shown in
Figure
13-10.
DMZ
Note: There can be
one or two DMZs.
Private
Internet
Network
Firewalls
Web Switches
Web Switches

Figure 13-10 Typical Firewall Load-Balancing Topology with DMZ

The DMZ servers can be attached to the Web switch directly or through an intermediate hub or
switch. The Web switch is then configured with filters to permit or deny access to the DMZ
servers. In this manner, two levels of security are implemented: one that restricts access to the
DMZ through the use of Web switch filters, and another that restricts access to the clean net-
work through the use of stateful inspection performed by the firewalls.
n
Chapter 13: Firewall Load Balancing
349
212777-A, February 2002

Advertisement

Table of Contents
loading

This manual is also suitable for:

Web os 10.0

Table of Contents