Naomi Lv3Posted 31 Oct 2022 11:16
  
It is not ideal design proposal because other network doesn't have security.
zubairhassan Lv2Posted 28 Oct 2022 22:27
  

Router:
1. interface facing the ISP
2. interface facing the NGAF

NGAF:
1. interface facing the Router
2. interface facing the Servers
DMZ Zone
1. IP address of the server is based on the NGAF
2. Default gateway IP addresssame with first router
RegiBoy Lv5Posted 26 Oct 2022 14:14
  
Last edited by RegiBoy 31 Oct 2022 11:06.

Yes, IP re-addressing is a must.

Router:
1. interface facing the ISP
2. interface facing the NGAF

NGAF:
1. interface facing the Router
2. interface facing the Servers


Although the design is not totally wrong, you don't maximize the protection and you leave the Switch and other Routers unprotected.
Newbie308427 Posted 26 Oct 2022 12:15
  
hi! imo exposing public area to internet without any AF is not a good idea
rivsy Lv5Posted 25 Oct 2022 15:48
  
Last edited by rivsy 25 Oct 2022 15:54.

For the Public IP Area
1. IP address to the endpoint is based on the first router .
2. For this setup, Public Area will not be protected from threat, cannot be managed by NGAF and have security consent since connection is direct to the first router.
3. Static IP for the 3 router in the Public Area
4. Default gateway IP address same with first router

For the DMZ Zone
1. IP address of the server is based on the NGAF
2. Default gateway IP addresssame with first router

I Can Help:

Change

Moderator on This Board

0
2
4

Started Topics

Followers

Follow

67
14
3

Started Topics

Followers

Follow

3
0
2

Started Topics

Followers

Follow

1
131
3

Started Topics

Followers

Follow

Board Leaders