Intel 9525, 9515, 9535 manual Introduction, About This Document, References, What is a DMZ

Page 4

DMZ Firewall Solution for the Express Router

1 Introduction

1.1About This Document

This document explains how to configure a secure Internet solution using the second LAN interface of the Intel® Express router as a DMZ. The DMZ setup is explained through the use of two example solutions, a Single IP Address Solution and Multiple IP Address.

It assumed that you have a solid understanding of networking concepts and experience in using the Express Router.

1.2References

[1]Intel Express Router User Guide

The user guide for your router explains in detail the basic configuration procedures used in the set up of the DMZ.

[2]Brent Chapman, Elizabeth D. Zwicky, “ Building Internet Firewalls”, 1995 O’Reilly & Associates. ISBN: 1-56592-124-0

1.3What is a DMZ

For an Intel Express Router having two LAN ports, you can setup a DMZ (DeMilitarized Zone) to increase security on your private network. A DMZ is a network off one of the LAN ports that acts as a kind of buffer between the external (public Internet) network and your secure network on the other LAN interface. The DMZ gives access to services required from both the external network and the secure network. The services are typically HTTP/FTP (Web) servers for public access, an HTTP/FTP proxy server, an SMTP server and a News (proxy) server. Mail servers and News servers for internal use are placed on the secure network. Through the use of IP filters, you prohibit access from the Internet to your secure network while still providing access to services on the DMZ.

 

192.168.151.0

 

Demilitarized Zone

 

Http/FTP

Http/FTP

News

 

(Web)

 

proxy

 

proxy

 

server

 

server

 

server

 

 

 

 

 

 

 

 

SMTP

Internet users are allowed

 

 

server

 

10/100

 

to access your Web

 

 

 

and FTP servers

 

 

 

 

 

LAN2 port

192.168.152.0

Main LAN

File

Mail

server

server

 

LAN1 port

Intel Express

router Internet

IP filters on the router block unwanted traffic destined to the main LAN

10/100

PC

PC

07-12-99

Version 1.0

3

Image 4
Contents DMZ Firewall Solution Copyright 1999, Intel Corporation. All rights reserved Table of Contents What is a DMZ IntroductionAbout This Document ReferencesIP Filters in the Express Router General Setup and ConsiderationsIP Address Selection Routing Setup DNS SetupMail Smtp Setup FTP SetupStatic Routing Setup DMZ Single IP Address SolutionNetwork Address Translation NAT Setup IP Filters Setup SettingsEntry Function Receive Rx Filters on LAN1Filter Function Transmit Tx Filters on LAN1Src. address 10.2.0.2 Src. port Action Pass Protocol 2 LAN2 Filters Receive Rx Filters on LAN2Filter Function Settings RIPTransmit Tx filters on LAN2 Settings Internet Connection Filters Receive Rx Filters on the connection to the InternetAction Pass Protocol UDP Transmit Tx Filters on the Connection to the Internet DMZ Multiple IP Address Solution IP Address AssignmentNetwork Address Translation NAT Transmit Tx Filters on LAN1 Settings Src. port Action Pass Protocol Dest. address type All Dest port Src. address type All Src. port Action Discard Protocol Action Discard Protocol Transmit Tx filters on LAN2 Src. port 1023 Action Pass Protocol UDP Transmit Tx Filters on the Connection to the Internet