Making DMZ isolated networks safe
My question concerns security around DMZ isolated networks. If the DMZ(s) are connected to a centralized storage device -- SAN or NAS -- what are the security implications? Would we be bridging the FW?

    Requires Free Membership to View

    When you register for SearchStorage.com, you’ll also receive targeted emails from my team of award-winning editorial writers. Our goal is to keep you informed on the hottest topics, the latest news and the biggest challenges you face as a storage professional today.

    Rich Castagna, Editorial Director

    By submitting your registration information to SearchStorage.com you agree to receive email communications from TechTarget and TechTarget partners. We encourage you to read our Privacy Policy which contains important disclosures about how we collect and use your registration and other information. If you reside outside of the United States, by submitting this registration information you consent to having your personal data transferred to and processed in the United States. Your use of SearchStorage.com is governed by our Terms of Use. You may contact us at webmaster@TechTarget.com.

Based on the little information you have provided, yes, the NAS/SAN are in effect providing a bypass to the firewall. There are two aspects to consider here:

1. Separating the SANs between the one in DMZ and one in the backend network.

2. Improving security of the NAS/SAN so it does not become the path of least resistance for attacks.

Editor's note: Do you agree with this expert's response? If you have more to share, post it in one of our .bphAaR2qhqA^0@/searchstorage>discussion forums.

This was first published in April 2004