dmz question

Hi All,

a project leader is proposing to represent all our _internal_ servers in our internal network on the outside of our internal firewall in our dmz each with an unique officially obtained _public_ ip-address. The obtained subnet will not be routed over the internet. His main argument is that we are dealing on the other side of the dmz with a company that manages our office network that maintains it's own ip-address policy and that we must be able to switch to another office IT provider without changing ip-addresses.

Besides that it will be difficult to obtain /22 public ip- addresses (we're talking about +- 500 servers), my opinion is that you don't do this, just because it's against common practice, which, as an argument, does not make an impression, as you can imagine and that this will not be inherently safe (failing of the acl on the outside firewall exposes the internal network).

What other arguments are there against this proposal?

What solutions are there that with a minimum of public addresses in the dmz, you can make 100-ths of internal servers available?

Sincerely,

Jan.

PS For those who can't imagine the layout:

internet | external firewall | external servers----------dmz------------|office providers firewall | internal firewall | internal servers

read more and respond »

Posted 5 years ago by John Smith in Networking Firewalls

Report misuse

Image for dmz question