Great Circle Associates Firewalls
(July 1994)
 

Indexed By Date: [Previous] [Next] Indexed By Thread: [Previous] [Next]

Subject: UDP thru Firewall (Was: Prospero protocol and filters)
From: plarkin @ iphase . com (Patrick Larkin Jr)
Date: Thu, 21 Jul 1994 11:41:13 -0500 (CDT)
To: firewalls @ greatcircle . com
Reply-to: plarkin @ iphase . com

In article <9407210641 .
 AA22761 @
 cwa .
 com>, uunet!cwa .
 com!dmurphy @
 iphase .
 com (Dan M
urphy) writes:
> Unless I'm mistaken, archie (and xarchie) use UDP, not TCP. Most of the
> networks belonging to the "anything not permitted is forbidden" school,
> I believe, tend to drop all UDP traffic as inherently insecure.

So, what are the risks of letting UDP thru the firewall onto any
internal machine?  We wanted to use SOCKS to proxy (most) everything
so that we can get user accounts off our bastion and deny any 
packet not from the bastion from getting in. This does break archie.

I'm told there is a socks-like thing that operates on UDP.

Any thoughts or suggestions on the risks and administration complexity 
of allowing UDP in vs using this proxy thing?

Thanks,
-- 
+========================================================================+
| PATRICK H LARKIN, JR. - System Administrator, Interphase Corp, Dallas  |
|>----------------------------------------------------------------------<|
| Internet: PLarkin @
 Iphase .
 COM  | Home: ..uunet!iphase!mustang!patrick   |
| Compuserve:  "Why?"           | MCI-Mail: (forwarded to Compuserve)    |
|   FaxNet: (214) 919-9200      |  Prodigy: "You've GOT to be kidding"   |
+========================================================================+


Follow-Ups:
Indexed By Date Previous: RE: Security of Appletalk and Dial back modems
From: Mark Verber <verber @ parc . xerox . com>
Next: Re: Security of Appletalk and Dial back modems
From: Perry The Cynic <perry @ sutr . cynic . org>
Indexed By Thread Previous: feedback on the likes of plug-gw
From: jimc @ e-Commerce . Com (Jim Carroll)
Next: Re: UDP thru Firewall (Was: Prospero protocol and filters)
From: ericm @ MicroUnity . com (Eric Murray)

Google
 
Search Internet Search www.greatcircle.com