Dual Homed Host Architecture
This setup consists of a host machine with two or more IP addresses for each of its physical port. One port is connected to intranet and other to the Internet. These ports act as its two way interfaces. Data forwarding through IP address is blocked on this machine thus there is no direct communication between local network and the Internet .
The communication between local network and the Internet occurs in either of two ways:
•Local network users are given accounts on the Dual Homed Host machine. In order to access the Internet they must login on the host machine
•Host machine runs a proxy program for each permitted service. Users can access the Internet through this proxy application. In this case login is not always required
Advantages
• More secure than Screening Router scheme
• Provides better access control
Disadvantages
• Since packet forwarding is disabled, a proxy must exist for all services that pass through host machine
• Not all services can have proxies and might require manual configuration or user input
• Firewall performance is limited to the performance of the host machine
• Only Dual Homed Host machine could be accessed from the Internet thus its security is at greater risk