Great Circle Associates Firewalls
(January 1995)
 

Indexed By Date: [Previous] [Next] Indexed By Thread: [Previous] [Next]

Subject: Anonymous FTP on Firewall
From: Tony Lorimer <tlorimer @ au . mdis . com>
Date: Wed, 18 Jan 1995 09:43:08 +1100 (EST)
To: firewalls @ greatcircle . com

Hello All,

I am after some advice, thoughts, advantages, disadvantages on what would be
the best solution for allowing anonymous ftp on my firewall. 

Situation:

My network is a typical setup:

                 INTERNET
                    |
                    |
                 FIREWALL
                    |
                    |
      ------------------------ Private Net
           |
        MACHINE A

I currently have an archive storage on Machine A that I want to allow access
to as anonymous ftp. I am currently restricted to the above configuration, due 
to lack of hardware resource etc etc. 

I have two ideas on how to allow access from the net to this machine.

1.	Setup the anonymous ftp server on Machine A and setup the appropiate 
	entries in /etc/netperm table to fire up plug-gw to pass through the
	connection to machine A.

2.	Setup the anonymous ftp server on the firewall and NFS mount machine A's
	file system onto the firewall. This will obviously stop access to an 
	internal machine via plug-gw but what about all the security concerns 
	with NFS.

Has anyone done any of the above approaches ?. Is there a better way ?.
I await your comments and feedback.

Thanks

			  
--------------------------------------------------------------------------

Tony Lorimer 	(tlorimer @
 au .
 mdis .
 com)         Phone:  +612 4365700
MDIS - McDonnell Information Systems Pty Ltd   Fax  :  +612 4392439
Sydney Australia                               Voice:  +612 4365751
--------------------------------------------------------------------------


Indexed By Date Previous: Details: Re: Cisco logging
From: Robert Sargent <sargent @ orsun . saic . com>
Next: Re: Cisco Logging
From: "Alec H. Peterson" <chuckie @ panix . com>
Indexed By Thread Previous: Details: Re: Cisco logging
From: Robert Sargent <sargent @ orsun . saic . com>
Next: Re: Anonymous FTP on Firewall
From: Ken Hardy <ken @ bridge . com>

Google
 
Search Internet Search www.greatcircle.com