You would need a seperate server to in the DMZ to run the BES Router service. You then need open ports for the BES to talk to it's router. That still leaves a way in. If I can get to oyur Router, I could use those open ports to get into your network.
All BES requires is port 3101 OUTBOUND to be open. It's as secure as can be.
|