Jump to content

Recommended Posts

Posted (edited)

I'll draw a pretty picture if needed....However.....

 

I have a Sophos XG With WAN/LAN/DMZ

 

I have CCTV PC with two physical NICs, NIC#1 LAN & NIC#2 CCTV(DMZ).

 

We have a physically different CCTV infrastructure not connected to the LAN infrastructure.

 

I have a CCTV CAM connected to DMZ, Goes to the internet etc etc

 

If i connect the CCTV PC's NIC#1 to our LAN, and the NIC#2 to our CCTV (DMZ)....... Will a PC act as a bridge/router/gateway between networks and be a security issue to the LAN if the DMZ is compromised?

 

I feel like there should be something in Windows Firewall that i need to do.

 

Any thoughts?

Edited by Jaan
Posted

No it won't route without extra configuration/software. You can have a PC with a NIC on a different network and connect to devices on that network, I do this at home as I have separate vlans and been on VPN disconnects me from been able to get to other stuff.

 

To be honest I'd either jus route the CCTV through the DMZ and control the access on the firewall and not let DMZ/CCTV traffic touch your internal client network at all. Or create an extra network on the firewall for the CCTV which might be an even better idea.

Posted
No it won't route without extra configuration/software. You can have a PC with a NIC on a different network and connect to devices on that network, I do this at home as I have separate vlans and been on VPN disconnects me from been able to get to other stuff.

 

To be honest I'd either jus route the CCTV through the DMZ and control the access on the firewall and not let DMZ/CCTV traffic touch your internal client network at all. Or create an extra network on the firewall for the CCTV which might be an even better idea.

 

Thanks for this.... yeah this is what i want to do. Create a new zone on the xg and drop the CCTV onto that... the reason a wanted the PC with two nics, is that if i want to access footage from the cameras (camera based storage) instead of going out to the WAN and back in on the DMZ, the CCTV PC can just directly access the CAMs internally and pull footage.....

  • Thanks 1
Posted
Thanks for this.... yeah this is what i want to do. Create a new zone on the xg and drop the CCTV onto that... the reason a wanted the PC with two nics, is that if i want to access footage from the cameras (camera based storage) instead of going out to the WAN and back in on the DMZ, the CCTV PC can just directly access the CAMs internally and pull footage.....

 

Yep that should work, just stick an IP and subnet mask, no need for a gateway or DNS and it should work :-)

  • Thanks 1

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...