Great Circle Associates Firewalls
(August 1994)
 

Indexed By Date: [Previous] [Next] Indexed By Thread: [Previous] [Next]

Subject: screened host configuration
From: dmargrav @ clark . net (David T. Margrave)
Date: Mon, 01 Aug 1994 16:09:13 -0400
To: firewalls @ greatcircle . com

Any opinions on this?

The definition of a "screened host gateway" specifies that the firewall shall
consist of a screening router which blocks traffic to all internal hosts except
the bastion host.

My question is whether or not it would be a good design compromise to move the 
bastion host to the outside.  Then the screening router would be configured to 
block traffic to all internal hosts, except for traffic originating from the 
bastion host.  These crude ASCII drawing may help clarify:


Normal:
                                      Bastion Host  
                                        |
Internet -----> Screening Router -------|
                                        |
                                      Inside Network 



Modified:


            Bastion Host 
              |  
Internet -----|-----> Screening Router ----> Inside Network



The reason I would like to do this is because I plan to implement the TAMU 
Drawbridge as the packet filter, and to have the TAMU Monitoring utilities 
running on a Sun *outside* the packet filter.  To include a bastion host
in this arrangement would require another Sun *inside* the packet filter, 
unless it is a workable compromise to combine the TAMU Montitoring utilities 
and the bastion host proxy agents on a single Sun outside the packet filter.

Would it be better to have the single Sun (running the TAMU Monitoring 
utilites and the proxy agents) placed inside the packet filter.  Is there a 
tradeoff
between enhanced security and monitoring capability here?


Thanks,

David Margrave
   



Follow-Ups:
Indexed By Date Previous: Re: University Security
From: bret @ real . com (Bret McDanel)
Next: Re: screened host configuration
From: johns @ oxygen . house . gov (John Schnizlein)
Indexed By Thread Previous: Request for info : Mosaic/firewalls/proxies
From: tims login <Shaw . Tim @ uniface . nl>
Next: Re: screened host configuration
From: paul @ hawksbill . sprintmrn . com (Paul Ferguson)

Google
 
Search Internet Search www.greatcircle.com