Can the Router be safely placed outside the TCP/IP firewall?
A. Yes, if certain precautions are taken. Warning: This should be done only by persons familiar with IP security issues. The APPX Router can be placed on the “dirty” side of the firewall or in a DMZ, so long as certain precautions are taken. General access to the Router machine must be prevented. This is most easily accomplished by setting up a packet filter on the IP router connecting to the internet (the “external” router). This packet filter should prevent any connections to the APPX Router except to TCP ports specifically assigned to APPX Router Listeners. Second, it is strongly recommended that IP Security be enabled in NT – this is done by checking the “Enable Security” checkbox on the “Advanced IP Addressing” panel accessed via the Advanced button on the TCP/IP properties page. Once enabled, security should be set up to allow only the TCP ports required for listeners. No other IP access should be allowed without careful consideration, even basic services such as DNS should not b