Windows Vista Forums
Vista Forums Home Join Vista Forums Windows 7 Forum Vista Tutorials Tags
Welcome to Windows Vista Forums. Our forum is dedicated to helping you find solutions with any problems, errors or issues you are experiencing with Windows Vista. The Vista forum also covers news and updates and has an extensive Windows Vista tutorial section that covers a wide range of tips and tricks.

Go Back   Vista Forums > Misc Newsgroups > Virtual Server

Vista - DMZ/Inernal LAN Setup

Reply
 
Old 08-11-2008   #1 (permalink)
bitter32


 
 

DMZ/Inernal LAN Setup

Hi All,

I'm trying to determine if I can securely setup a single Host server
(Virtual Server or Hyper-V) hosting two VMs in the following way:

1. One VM is connected to Public DMZ
2. One VM is connected to internal network.
3. Each VM will have dedicated physical network connection.
4. Cisco Firewall rules will allow communication between DMZ and Internal
server.
5. Maximize security. How do you protect internal network if DMZ VM is
compromised?
6. Host server does not need to communicate with either VM, but VM
administration is still required from the host.

Would a 3 nic host server be required?
How would I cofingure each network connection?

Thanks!

My System SpecsSystem Spec
Old 08-12-2008   #2 (permalink)
Bill Grant


 
 

Re: DMZ/Inernal LAN Setup



"bitter32" <bitter32@xxxxxx> wrote in message
news:3C1296B1-BAB9-4110-A01A-F655255B25BA@xxxxxx
Quote:

> Hi All,
>
> I'm trying to determine if I can securely setup a single Host server
> (Virtual Server or Hyper-V) hosting two VMs in the following way:
>
> 1. One VM is connected to Public DMZ
> 2. One VM is connected to internal network.
> 3. Each VM will have dedicated physical network connection.
> 4. Cisco Firewall rules will allow communication between DMZ and Internal
> server.
> 5. Maximize security. How do you protect internal network if DMZ VM is
> compromised?
> 6. Host server does not need to communicate with either VM, but VM
> administration is still required from the host.
>
> Would a 3 nic host server be required?
> How would I cofingure each network connection?
>
> Thanks!
What would you use a third NIC for? I cannot think of any reason unless
you want to administer the host remotely.

If you are using a Cisco you must have a physical DMZ and private LAN. In
Hyper-V you would connect one NIC in the host to the DMZ, create a virtual
switch linked to this NIC and connect one vm to the network.

You would connect another NIC in the host to the internal network, create
a virtual switch and connect the other vm to that network. The situation
with Virtual Server would be similar but you do not need to create the
virtual switches. Virtual Server will automatically set up a virtual network
for each NIC in the host.

If your firewall is compromised, there is nothing you can do about it by
changing things on this server. Whether the server is a physical or virtual
machine makes no difference to the way networking operates. If a network is
compromised, all machines on that network are compromised.

My System SpecsSystem Spec
Reply

Thread Tools


Similar Threads
Thread Forum
Setup has now become Vista General II(Miscellaneous) instead of Setup Vista installation & setup
Setup can not run vista RC1 setup on XP pro? Vista General
Vista Beta 2 hangs during setup installation setup Vista installation & setup
Windows Setup: setup.exe - Application Error Vista installation & setup
Windows Setup: setup.exe - Application Error Vista installation & setup


Vista Forums is an independent web site and has not been authorized,
sponsored, or otherwise approved by Microsoft Corporation.
"Windows Vista", the Start Orb, and related materials are trademarks of Microsoft Corp.
© Designer Media Ltd

1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 38 39 40 41 42 43 44 45 46