Great Circle Associates Firewalls
(April 1995)
 

Indexed By Date: [Previous] [Next] Indexed By Thread: [Previous] [Next]

Subject: Re: SLIP, firewalls, Netware 4.1
From: Brent @ GreatCircle . COM (Brent Chapman)
Date: Fri, 21 Apr 1995 00:02:03 +0000
To: firewalls @ greatcircle . com

>If you use this approach to treat dialins like "insiders," it doesn't
>do anything for the basic problem. Once your SLIP connection is
>processing "inside" packets, it could give attackers a bridge inside
>if there's a second modem on your home machine. The ultimate breach,
>of course, is to connect the second modem to your local Internet
>provider and serve as a router for packets between the 'Net and
>inside. This neatly bypasses any filtering routers, firewalls, or
>other things defending the site.

So use filtering on your end of the SLIP (or PPP or whatever; MorningStar's
PPP product has pretty good packet filtering, and I think it does SLIP too,
but I'm not sure) line to limit packets to those coming to/from the IP
address of the legitimate home machine (plus whatever further restrictions
you feel are appropriate).


-Brent

----------------------------------------------------------------------
For info about the Internet Security Firewalls Tutorial and a schedule
of upcoming dates, please send email to Tutorial-Info @
 GreatCircle .
 COM
----------------------------------------------------------------------
Brent Chapman                                 Great Circle Associates
Brent @
 GreatCircle .
 COM                         1057 West Dana Street
+1 415 962 0841                               Mountain View, CA  94041



Indexed By Date Previous: [no subject]
From: patrick @ oes . amdahl . com (Patrick Horgan)
Next: Re:
From: Brent @ GreatCircle . COM (Brent Chapman)
Indexed By Thread Previous: Re: SLIP, firewalls, Netware 4.1
From: mgc1 @ iaccess . com . au (Mark Christian)
Next: ISBN of book
From: "RG Ferris 871-2157" <0139427 @ nptmc . eskom . co . za>

Google
 
Search Internet Search www.greatcircle.com