|
Based on the little information you have provided, yes, the NAS/SAN are in effect providing a bypass to the firewall. There are two aspects to consider here:
1. Separating the SANs between the one in DMZ and one in the backend network.
2. Improving security of the NAS/SAN so it does not become the path of least resistance for attacks.
Editor's note: Do you agree with this expert's response? If you have more to share, post it in one of our discussion forums.
|