Skip to Main Content

Infrastructure Software

Announcement

For appeals, questions and feedback about Oracle Forums, please email oracle-forums-moderators_us@oracle.com. Technical questions should be asked in the appropriate category. Thank you!

Zones in a DMZ

807559Sep 5 2008 — edited Oct 8 2008
I have a request to place a Solaris 10 machine into a publicly facing DMZ. It will contain multiple zones. Fine.

However one non-global zone is being requested to be in the internal network, and the rest in the DMZ. I don't like this from a security point of view - though I'm not quite knowledgeable enough on Zones to articulate why, just deep distrust about breaking the traditional model of actual separation by firewall between the internal and external networks.

Could anybody point me to the Sun position on this? Or share your own ideas? I understand networking is still somewhat shared between zones and note some recent exploits that at least show proof of concept on obtaining access to other zones:
http://sunsolve.sun.com/search/document.do?assetkey=1-66-240866-1

Many thanks!
Comments
Locked Post
New comments cannot be posted to this locked post.
Post Details
Locked on Nov 5 2008
Added on Sep 5 2008
2 comments
352 views