Great Circle Associates Firewalls
(December 1994)
 

Indexed By Date: [Previous] [Next] Indexed By Thread: [Previous] [Next]

Subject: Admin effort
From: padgett @ tccslr . dnet . mmc . com (A. Padgett Peterson, P.E. Information Security)
Date: Thu, 29 Dec 94 20:47:52 -0500
To: "firewalls @ greatcircle . com"@UVS1.dnet.mmc.com

Note that since I do not get headers, on msgs that do not include addresses
I can only reply to the group - sorry).

>I work for a government agency and we currently go through an internet 
>provider for our internet services.  We are looking at setting up our own 
>connection to the internet by tapping into the backbone of our local 
>university.  As firewall administrators, I am curious as to the time and 
>effort necessary in maintaining a firewall on a day-to-day basis.

Would think this would be covered by a FAQ but the answer must be hedged
depending on the complexity of the connection. If all you want is E-mail,
otward Telnet & FTP, it is really pretty easy, just turn everything off
except those three and only allow inward to Mail.

Now if you want Network News delivered to your server and you want your
own web server etc. etc. etc. things can get very complicated very fast
so it is a matter of:
1) Develop a plan of what services you need
2) Determine the accesses required
3) Then determine what kind of firewall is necessary (and that is just
   one piece of the entire envelope).

However, when designing a firewall a paraphrase of the immortal line 
spoken by Joe Don Baker in "Hunt for Red October" is in order: "Don't
take a dump without a plan."
					Warmly,
						Padgett


Indexed By Date Previous: Re: Firewall-1 toolkit from Checkpoint
From: Marc_Mangus @ ccmail . geoworks . com
Next: Re: Ethernet snooping tool?
From: John Hawkinson <jhawk @ panix . com>
Indexed By Thread Previous: Re: your mail
From: Marcus J Ranum <mjr @ tis . com>
Next: Re: your mail
From: "Michael S. Hines" <MSHINES @ freh-02 . adpc . purdue . edu>

Google
 
Search Internet Search www.greatcircle.com