Create a Post
cancel
Showing results for 
Search instead for 
Did you mean: 
bad_joojoo
Participant
Jump to solution

Gateway Topolgy - Internal, External or DMZ ?

Hi all,

 

Just looking at a scenario and asked a question around the correct "Topology" for interfaces connecting to other manufacturer firewalls. In this scenario, CP Gateway is the Internal firewall protecting the hosted Data Centres. There are links to other firewalls which provide ongoing connectivity to the varying customers networks, and links to similar with a DMZ hosting proxy services (Web, Email, etc).

My question is, should the interconnecting links be consider Internal, DMZ or External?

CP_Gateway_Topology.png

Cheers

Ju

 

 

0 Kudos
1 Solution

Accepted Solutions
PhoneBoy
Admin
Admin

External should used for interfaces that can be used to reach the Internet (i.e. it has the default route).
Which means your interface pointing towards the upper Palo (which has the Internet connected) should be marked as external.
The interface pointing towards the customer networks can be marked as a DMZ.

View solution in original post

(1)
4 Replies
Chris_Atkinson
Employee Employee
Employee
(1)
the_rock
Legend
Legend

To me, logically, I would say DMZ, based on your diagram. 

0 Kudos
(1)
PhoneBoy
Admin
Admin

External should used for interfaces that can be used to reach the Internet (i.e. it has the default route).
Which means your interface pointing towards the upper Palo (which has the Internet connected) should be marked as external.
The interface pointing towards the customer networks can be marked as a DMZ.

(1)
bad_joojoo
Participant

Many thanks all for your replies, Kind Regards Ju

0 Kudos

Leaderboard

Epsum factorial non deposit quid pro quo hic escorol.

Upcoming Events

    CheckMates Events