Great Circle Associates Firewalls
(December 1994)
 

Indexed By Date: [Previous] [Next] Indexed By Thread: [Previous] [Next]

Subject: Re: Bastion hosts vs bridges
From: criney1 @ abacus . tis . tandy . com (Chris Riney)
Date: Tue, 20 Dec 1994 13:50:00 -0600 (CST)
To: isdmill @ gatekeeper . ddp . state . me . us (David Miller)
Cc: firewalls @ greatcircle . com
In-reply-to: <Pine . 3 . 89 . 9412201242 . A6570-0100000 @ gatekeeper . ddp . state . me . us> from "David Miller" at Dec 20, 94 01:08:40 pm

> 
> First, a hearty thank you to all those who replied to my fwtk vs seal
> question last week.  I got a lot of quality replies that pretty much said 
> that fwtk is plenty good, and that the most important factors are the 
> knowledge and ability of the administrator and the site security policy.
> 
> Next question....
> 
> While suggesting a firewall for my organization myself, we have another 
> gentleman who insists he can do everything with filters in his bridge 
> that I can do with a firewall.
> 
> I would greatly appreciate hearing your best arguments for or against 
> bridge filters vs a firewall as far as security is concerned.
> 
> ----------------------------------------------------------------------------
> 		It's *amazing* what one can accomplish when 
> 		    one doesn't know what one can't do!
> 

Most of the firewall tutorials and guides recommend that a firewall consist
of a mix of routers and bastion-hosts.  I'd be suprised if your friend could
implement a proxy server with his filters (Am I missing something, or don't
most filters on router only determine who can get through the router, not
interperate/massage/authenticate the data)!

You use filters on a router (on both sides of the DMZ leg) to determine who
can get into the DMZ and where in the DMZ they can go.  You have a
BASTION HOST in the DMZ to allow connectivity between the two sides of the
DMZ.  Without the bastion host, you (in most likely hood) would be updating
the filters on a TO frequent of a bases, when someone on your side of the DMZ
want's to go to a diffent host on the other side of the DMZ.


Bastion-hosts and router-filters cover different aspects of security in
a firewall environment.  Without a delicate balance of both, you are
usually just inviting trouble.



References:
Indexed By Date Previous: Filtering by service providers
From: Bob Stratton <strat @ uunet . uu . net>
Next: RE: tcp_wrapper.ps.Z's log file ?
From: bwong @ outpost . sbi . com (Bik Yee Wong)
Indexed By Thread Previous: Bastion hosts vs bridges
From: David Miller <isdmill @ gatekeeper . ddp . state . me . us>
Next: PPP and plug-gw
From: system PRIVILEGED account <root @ wu1 . wl . aecl . ca>

Google
 
Search Internet Search www.greatcircle.com