Adding a perimeter network (DMZ) with UTM, what's best practice for small business?

B

Bill Seymour

I've got a client with about 25 computers on their local network (Active Directory domain) who's interested in upping their security a bit by moving an externally addressable FTP server to a DMZ, configuring a proxy server between the internal network and the DMZ to route traffic through to the internet and putting a UTM package at that proxy server. In addition some AD users need remote access to their internal machines. They have a FortiGate router/firewall on the internet side that provides some level of protection but is a devil to get VPN working. I'd like to do the whole DMZ to internal package with a Dell server I have running Server 2016 Std with RRAS for the VPN.

Am I pointing in the wrong direction, or does that seem like a viable plan? How best to implement the various pieces, Hyper-V and Sophos UTM, OPNSense, pfSense, other? Do I setup a forward proxy in Windows Server or handle that with some other package? What am I missing that's going to bite me in the a** in the next couple of months? :)

Continue reading...
 
Back
Top Bottom