Great Circle Associates Firewalls
(May 1994)
 

Indexed By Date: [Previous] [Next] Indexed By Thread: [Previous] [Next]

Subject: requiring PTR records
From: hobbit @ bronze . lcs . mit . edu (*Hobbit*)
Date: Wed, 25 May 94 08:49:43 EDT
To: firewalls @ greatcircle . com

While at FTP, I went around tcpd-izing machines, and had configured tcpd on the
"accessible" machines to require valid DNS PTRs as well as matching As.

A lot of people thought this was horribly restrictive.  My argument was that we
wanted to only accept connections from machines for which *someone* had taken
responsibility by placing them in their DNS files, which doesn't buy you all
that much when it still lets in things like "public-dialup-port6.boston-ppp.
psi.net" ...  Since there wasn't really any stated policy one way or the other,
it was just a perpetual pissing fight.

_H*

Indexed By Date Previous: Re: Allowing Magic Kingdom Access.
From: "John P. Rouillard" <rouilj @ terminus . cs . umb . edu>
Next: Re: Allowing Magic Kingdom Access
From: MICHAEL NITTMANN <NITTMANN @ UWLAX . EDU>
Indexed By Thread Previous: S/Key and Kerberos
From: yerkes_chuck @ jpmorgan . com
Next: Re: Allowing Magic Kingdom Access
From: MICHAEL NITTMANN <NITTMANN @ UWLAX . EDU>

Google
 
Search Internet Search www.greatcircle.com