- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Creating a DMZ with pair of mx250
I have a pair of mx250 on our network boundary set with required policies and rules and all is ok.
Im looking at creating a sperate network within our network to keep some kit seperate (by hardware) for the rest of the network.
I want to have a dmz there between 2 new mx250 to control traffic in and out.
Is there any thing special or different I should do with the 2 MX that would suit a dmz / restricted network companed to the setup of mx250 for boundary / isp connections ?
Also to make them more secure should I have the dmz / mx250 / switches in the new restricted network in a seperate dashboard in case account is compromised ?
Are there any issues with having 2 seperate dashboards in the one site ?
- Labels:
-
Firewall
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Take a look at this.
Please, if this post was useful, leave your kudos and mark it as solved.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
It is very similar.
Typically you would create firewall rules between the DMZ and the inside of your network to limit an infected DMZ machine from spreading to internal devices.
Typically you just NAT into the DMZ from your public IP address space (which creates a natural type of firewall rules for inbound traffic to the DMZ from the Internet).
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
We use WAF rules on a (non Meraki) firewall for WAN to DMZ and then normal rules from DMZ to LAN for any access required there as @PhilipDAth mentioned above. I'm not sure if the MXs can act as a Web Application Firewall (WAF), the L7 rules might work like that.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
No, the MX cannot act as a WAF due to various limitations, the best thing would be to have a system like a BIG-IP to work with WAF.
Please, if this post was useful, leave your kudos and mark it as solved.
