<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: DMZ vs NAT - pros and cons in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/DMZ-vs-NAT-pros-and-cons/m-p/139398#M21277</link>
    <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;now my "opponent" precised what he means by NAT. He made actually an DMZ with private IP address range, which uses a 1:1 static NAT for particular hosts .&amp;nbsp;&lt;/P&gt;&lt;P&gt;Does it have any advantage comparing to DMZ having public address range ?&amp;nbsp;&lt;/P&gt;&lt;BLOCKQUOTE&gt;&lt;HR /&gt;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/7"&gt;@PhoneBoy&lt;/a&gt;&amp;nbsp;wrote:&lt;BR /&gt;&lt;P&gt;It’s not really an either-or.&lt;BR /&gt;Some do both.&lt;BR /&gt;A DMZ is really about segmentation.&lt;BR /&gt;More precisely, a DMZ is about ensuring all externally accessible resources can only access internal security resources via some form of access control (if allowed at all).&lt;/P&gt;&lt;P&gt;None of that is Check Point specific.&lt;/P&gt;&lt;HR /&gt;&lt;/BLOCKQUOTE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Tue, 25 Jan 2022 13:22:44 GMT</pubDate>
    <dc:creator>Libor_Kovar</dc:creator>
    <dc:date>2022-01-25T13:22:44Z</dc:date>
    <item>
      <title>DMZ vs NAT - pros and cons</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/DMZ-vs-NAT-pros-and-cons/m-p/134395#M20131</link>
      <description>&lt;P&gt;Hi all,&lt;/P&gt;&lt;P&gt;could you comment pls, what is better for security, whether DMZ or NAT (Static or port NAT ) and why ?&lt;/P&gt;&lt;P&gt;Some say, contrary to me, that NAT is more secure and DMZ is insecure and obsolete.&lt;/P&gt;&lt;P&gt;What is you opinion&amp;nbsp; ?&lt;/P&gt;&lt;P&gt;I suppose Checkpoint FW context.&lt;/P&gt;&lt;P&gt;I appreciate modern info sources about that, eventually.&lt;/P&gt;&lt;P&gt;Thanks LK&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 18 Nov 2021 14:20:17 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/DMZ-vs-NAT-pros-and-cons/m-p/134395#M20131</guid>
      <dc:creator>Libor_Kovar</dc:creator>
      <dc:date>2021-11-18T14:20:17Z</dc:date>
    </item>
    <item>
      <title>Re: DMZ vs NAT - pros and cons</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/DMZ-vs-NAT-pros-and-cons/m-p/134460#M20150</link>
      <description>&lt;P&gt;It’s not really an either-or.&lt;BR /&gt;Some do both.&lt;BR /&gt;A DMZ is really about segmentation.&lt;BR /&gt;More precisely, a DMZ is about ensuring all externally accessible resources can only access internal security resources via some form of access control (if allowed at all).&lt;/P&gt;
&lt;P&gt;None of that is Check Point specific.&lt;/P&gt;</description>
      <pubDate>Fri, 19 Nov 2021 05:36:44 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/DMZ-vs-NAT-pros-and-cons/m-p/134460#M20150</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2021-11-19T05:36:44Z</dc:date>
    </item>
    <item>
      <title>Re: DMZ vs NAT - pros and cons</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/DMZ-vs-NAT-pros-and-cons/m-p/139398#M21277</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;now my "opponent" precised what he means by NAT. He made actually an DMZ with private IP address range, which uses a 1:1 static NAT for particular hosts .&amp;nbsp;&lt;/P&gt;&lt;P&gt;Does it have any advantage comparing to DMZ having public address range ?&amp;nbsp;&lt;/P&gt;&lt;BLOCKQUOTE&gt;&lt;HR /&gt;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/7"&gt;@PhoneBoy&lt;/a&gt;&amp;nbsp;wrote:&lt;BR /&gt;&lt;P&gt;It’s not really an either-or.&lt;BR /&gt;Some do both.&lt;BR /&gt;A DMZ is really about segmentation.&lt;BR /&gt;More precisely, a DMZ is about ensuring all externally accessible resources can only access internal security resources via some form of access control (if allowed at all).&lt;/P&gt;&lt;P&gt;None of that is Check Point specific.&lt;/P&gt;&lt;HR /&gt;&lt;/BLOCKQUOTE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 25 Jan 2022 13:22:44 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/DMZ-vs-NAT-pros-and-cons/m-p/139398#M21277</guid>
      <dc:creator>Libor_Kovar</dc:creator>
      <dc:date>2022-01-25T13:22:44Z</dc:date>
    </item>
    <item>
      <title>Re: DMZ vs NAT - pros and cons</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/DMZ-vs-NAT-pros-and-cons/m-p/139406#M21279</link>
      <description>&lt;P&gt;From a regulatory perspective, PCI-DSS for example mandates that no connection from an untrusted network i.e. partner or the internet is allowed to terminate in a trusted network, thus forcing you to use DMZ's.&amp;nbsp;&amp;nbsp;You will find that many other frameworks (CIS, NIST etc.) also require, or at least strongly recommend, the use of external-facing DMZ's.&lt;/P&gt;
&lt;P&gt;From a design perspective, I cannot see how a properly designed DMZ is more insecure than a straight NAT to the inside.&amp;nbsp; For one it will certainly complicate lateral movement post-breach.&lt;/P&gt;</description>
      <pubDate>Tue, 25 Jan 2022 13:49:53 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/DMZ-vs-NAT-pros-and-cons/m-p/139406#M21279</guid>
      <dc:creator>Ruan_Kotze</dc:creator>
      <dc:date>2022-01-25T13:49:53Z</dc:date>
    </item>
    <item>
      <title>Re: DMZ vs NAT - pros and cons</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/DMZ-vs-NAT-pros-and-cons/m-p/139416#M21282</link>
      <description>&lt;P&gt;It depends are those public IPs on your WAF/LB or actual hosts?&lt;/P&gt;
&lt;P&gt;It helps to provide a clearer picture or risk getting sub optimal advice.&lt;/P&gt;</description>
      <pubDate>Tue, 25 Jan 2022 14:10:50 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/DMZ-vs-NAT-pros-and-cons/m-p/139416#M21282</guid>
      <dc:creator>Chris_Atkinson</dc:creator>
      <dc:date>2022-01-25T14:10:50Z</dc:date>
    </item>
    <item>
      <title>Re: DMZ vs NAT - pros and cons</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/DMZ-vs-NAT-pros-and-cons/m-p/139424#M21284</link>
      <description>&lt;P&gt;Just generic hosts&lt;/P&gt;</description>
      <pubDate>Tue, 25 Jan 2022 14:38:24 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/DMZ-vs-NAT-pros-and-cons/m-p/139424#M21284</guid>
      <dc:creator>Libor_Kovar</dc:creator>
      <dc:date>2022-01-25T14:38:24Z</dc:date>
    </item>
    <item>
      <title>Re: DMZ vs NAT - pros and cons</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/DMZ-vs-NAT-pros-and-cons/m-p/139427#M21285</link>
      <description>&lt;P&gt;I suppose an argument could be made that NATting inbound traffic into a privately-addressed DMZ does provide some "security through obscurity" by hiding the server's true inside address from the outside world.&amp;nbsp; In some cases this true address will need to be known when trying certain types of exploit attempts against the server.&amp;nbsp; However there are so many ways that web servers in particular can leak their true IP address through error pages and such I'd say NATting really doesn't provide much security benefit, increases the complexity of the network slightly, and incurs some extra NAT processing on the firewall.&lt;/P&gt;</description>
      <pubDate>Tue, 25 Jan 2022 16:28:54 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/DMZ-vs-NAT-pros-and-cons/m-p/139427#M21285</guid>
      <dc:creator>Timothy_Hall</dc:creator>
      <dc:date>2022-01-25T16:28:54Z</dc:date>
    </item>
    <item>
      <title>Re: DMZ vs NAT - pros and cons</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/DMZ-vs-NAT-pros-and-cons/m-p/139428#M21286</link>
      <description>&lt;P&gt;Thanks, exactly my opinion. But you know , new hire &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 25 Jan 2022 16:01:33 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/DMZ-vs-NAT-pros-and-cons/m-p/139428#M21286</guid>
      <dc:creator>Libor_Kovar</dc:creator>
      <dc:date>2022-01-25T16:01:33Z</dc:date>
    </item>
    <item>
      <title>Re: DMZ vs NAT - pros and cons</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/DMZ-vs-NAT-pros-and-cons/m-p/139429#M21287</link>
      <description>&lt;P&gt;Thanks to all !&lt;/P&gt;</description>
      <pubDate>Tue, 25 Jan 2022 16:05:07 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/DMZ-vs-NAT-pros-and-cons/m-p/139429#M21287</guid>
      <dc:creator>Libor_Kovar</dc:creator>
      <dc:date>2022-01-25T16:05:07Z</dc:date>
    </item>
  </channel>
</rss>

