The simple answer is to keep publicly facing servers out of your internal LAN. If the server or device is internet facing, that means it has a greater attack surface. If someone hacks into the server, they are then on your internal network. If you have the server on the outside in a DMZ, then they can be isolated from your internal hosts if they are compromised.
Comment from None
Time April 7, 2010 at 4:14 pm
The simple answer is to keep publicly facing servers out of your internal LAN. If the server or device is internet facing, that means it has a greater attack surface. If someone hacks into the server, they are then on your internal network. If you have the server on the outside in a DMZ, then they can be isolated from your internal hosts if they are compromised.