Great Circle Associates Firewalls
(August 1994)
 

Indexed By Date: [Previous] [Next] Indexed By Thread: [Previous] [Next]

Subject: Re: VMS security - more detailed question
From: D . Michael . Francis @ DREP . DND . Ca
Date: Mon, 08 Aug 1994 15:07:39 -0700 (PDT)
To: Jim Carroll <jimc @ e-Commerce . Com>
Cc: firewalls @ GreatCircle . COM
In-reply-to: <9408081848 . AA08815 @ e-Commerce . Com>


On Mon, 8 Aug 1994, Jim Carroll wrote:

> Okay folks.  My question seems to be getting a tad misconstrued,
> possibly by the way I phrased it.
> 
> The company I'm trying to alert has a sysadmin who is confident that
> he's locked up his VMS host.  Yet, he's just now going through the
> process of purchasing TCP/IP for it.  Since TCP/IP is somewhat
> foreign/new to him, I'm concerned that he is building up a false sense
> of security, esp. when you consider that they have *no* firewall to
> speak of.
> 
> Comments?

As a VMS `firewall' builder and maintainer I'll reach out of my bastion 
and pick up that gauntlet. 
:)

As a _part_ of an overall security policy, a VMS platform can be 
adequately used as (or a part of) a firewall.  
Without starting, or stoking a flamewar, as it _has_ been stated before by 
others, VMS _out_of_the_box_ requires less knowledge and training to 
establish and maintain a more robust (aka secure) system than some other 
O/S's _out_of_the_box_ require, and I concur.

I'm using VMS platforms as a firewall - although, IMHO, firebreak would be 
more accurate, and if _I_ can do it, he can !
[Details by eMail, if you're interested]

I agree with Jim's concern about acquiring a TCP/IP package for VMS that 
will be placed in an exposed environment. Some are more suitable than 
others, and a knowledge of firewall philosophy would help with the 
selection. The best suggestion I can make, is for the `sysadmin' to 
obtain and read Cheswick and Bellovin.

> > -- 
> Jim Carroll --  jimc @
 e-Commerce .
 Com
> e-Commerce, Inc., 1030 Kamato Road, Suite 201
> Mississauga, Ontario, Canada    L4W 4B6
> Tel:  +1 905 602 0863    Fax:  +1 905 603 8402

Cheers,

D. Michael Francis  P.Eng                | D .
 Michael .
 Francis @
 Drep .
 DND .
 Ca
Manager, Central Computing Facility      | 1.604.363.5894
Defence Research Establishment Pacific   |
CFB Esquimalt, FMO Victoria B.C. V0S 1B0 | 37 Alberg `Sanderling'



References:
Indexed By Date Previous: Re: VMS security - more detailed question
From: "Comet" <COMET @ us . oracle . com>
Next: Cisco router config ala Cheswick and Bellovin?
From: "Andrew T. Rodnite" <rodnite @ holonet . net>
Indexed By Thread Previous: VMS security - more detailed question
From: jimc @ e-Commerce . Com (Jim Carroll)
Next: Re: VMS security - more detailed question
From: "Selden E. Ball, Jr." <SEB @ LNS62 . LNS . CORNELL . EDU>

Google
 
Search Internet Search www.greatcircle.com