|
You should leave it on the router, it'll reduce the traffic load on the workstation switch ports.
The public will be able to get access to it by either declaring it's MAC address as DMZ or you could setup a port forward to it.
There's a potential issue of having it behind the firewall. It can work that way, but if that server's gonna get beat on, then it's gonna slog your firewall. BUT - putting it outside of the firewall means that the machine itself will have to deal with all the crap that comes in across the 'net, plus it means that you'll have to have a 2nd IP address for it.
I bring this up in the scope of what your teacher is looking for. You may get bonus points for knowing that there are multiple ways of doing this "right".
Also.. is showing VPN part of the assignment? That's not common in a day-to-day public access network.
__________________
:: Mark
|