dedicated external ports

dedicated external ports

NewsGroups | Search | Tools
 comp.dcom.sys.cisco  Post an article  get this group's latest topics as an RSS feed add this group's latest topics to your My MSN content add this group's latest topics to your My Yahoo content  add this group's latest topics to your Google content  YahooMyWeb Yahoo!  Google Google  Windows Live Favorites Windows Live  del.icio.us del.icio.us  digg digg  Add to Netscape Netscape
Subject Author Date
dedicated external ports mmark751969 03-19-2007
Posted by on March 19, 2007, 3:34 pm
If you were  Registered and logged in, you could reply and use other advanced thread options
I have a number of catalyst 3750 stackable switches in the network.
We are on 5 floors, each floor has it's own catalyst stack which ties
into the core stack on the 1st floor. We are also layer 3 ip routing
capable and have a number of vlans defined. I have some requests to
run some dedicated ports, on other floors, that terminate to a switch
that's connected outside the firewall. I'm thinking the way i have to
do this is to define a vlan on an ip range that is defined on our
external static range. Then connect the ports in the other floors, to
access mode configured vlan ports at the floor switches and the core
switch. Then connect the core port to the external switch. If done
this way, i believe i'd have to route our external public address
range internally. Is there another way to do this. Thanks


Posted by Thrill5 on March 19, 2007, 8:40 pm
If you were  Registered and logged in, you could reply and use other advanced thread options
What you are contemplating is very, very insecure. You never, ever mix
inside network ports and outside network ports on the same network. Why,
because there are many different types of attacks and hacks that can very
easily gain access to you internal network once they have access to a
computer connected to the outside network. (Hacking isn't just layer 3!!!!)
If someone compromises one of the outside machines, there are many attacks
that can bring down your switches. The reason you have a firewall is to
prevent these types of attacks, so why are you by-passing it? If you
absolutely need to have these computers outside the firewall, put them on a
completely separate network, separate wires, separate switches, separate
routers. This is the only way to make sure that your internal network stays
secure. Do a search on "Layer 2 security"
http://www.google.com/search?q=layer+2+security

Scott

>I have a number of catalyst 3750 stackable switches in the network.
> We are on 5 floors, each floor has it's own catalyst stack which ties
> into the core stack on the 1st floor. We are also layer 3 ip routing
> capable and have a number of vlans defined. I have some requests to
> run some dedicated ports, on other floors, that terminate to a switch
> that's connected outside the firewall. I'm thinking the way i have to
> do this is to define a vlan on an ip range that is defined on our
> external static range. Then connect the ports in the other floors, to
> access mode configured vlan ports at the floor switches and the core
> switch. Then connect the core port to the external switch. If done
> this way, i believe i'd have to route our external public address
> range internally. Is there another way to do this. Thanks
>



Similar ThreadsPosted
Help: One External IP address to two Ports April 5, 2007, 1:33 pm
CCIE website dedicated to router virtualization and other topics... June 25, 2007, 4:54 pm
Internet access for remote site over dedicated T1 line w/ Cisco 1720s September 28, 2005, 5:21 pm
Facebook Group - dedicated to networking professionals, with an emphasis on Cisco Hardware/Technology. December 19, 2007, 9:46 am
Dedicated Point to Point T1 Connection via 2620 Routers September 9, 2008, 5:15 pm
Newbie: async mode dedicated versus async mode interactive!! June 8, 2006, 8:09 pm
Max. External LSA November 6, 2004, 9:37 am
PIX VPN using external addresses September 6, 2005, 5:33 pm
Howto hit an external ip with VPN September 27, 2005, 8:11 pm
PIX 515 Switch 8 External IPs October 24, 2005, 7:37 pm

other useful resources:
The Federal Communications Commission (FCC)
Telecommunications Industry Association
Electronic and Software Security Products and Services
International Telecommunication Union

Custom CGI Perl and PHP programming by 1-Script.com

Contact Us | Privacy Policy
The site map in XML format XML site map