I won't go into our screened gateway as it is described in papers already pointed
to (decuac.dec.com:/pub/docs/firewall/*). For people needing telnet access
from the outside, we use a Digital Pathways, Inc encryption device
(Mtn View, CA) -- although other companies make similar boxes I am sure --
and a server on the internal net which provides the external gateway with the
authentication challenge for the person trying to log in. Once authenticated
the user gets attached to a process which would allow access to internal nodes
(where they would then need their passwords, etc.),
F
Follow-Ups:
References:
|
|