Single firewall architecture with multiple IP subnets

As shown in the diagram below, a simple way to isolate the network resources without introducing another set of firewalls is to use multiple interfaces configured with multiple subnets. In the design, the web, application and database servers are placed in different subnets using different IP subnets with different security levels configured on interfaces. Let's assume that only one web server has to be exposed to the internet and the rest of the server will talk to the web server internally. This can be easily configured and controlled by inputting firewall rules. This can be achieved by exposing the web server to the internet and allowing an internet subnet policy. An attacker could ...

Get Practical Network Scanning now with the O’Reilly learning platform.

O’Reilly members experience books, live events, courses curated by job role, and more from O’Reilly and nearly 200 top publishers.