Great Circle Associates Firewalls
(October 1995)
 

Indexed By Date: [Previous] [Next] Indexed By Thread: [Previous] [Next]

Subject: Re: Firewall1 Comparison -Reply
From: fepotts @ fepco . com (Fred E Potts)
Date: Fri, 13 Oct 1995 18:38:59 -0700
To: dkaye @ rds . com
Cc: Firewalls @ GreatCircle . COM

Hi, Doug,

My thinking on this subject is that the best way to set up a firewall
system is:

0.	CSU/DSU

1.	Filtering Gateway (packet filter router)

2.	Application Gateway.

3.      Harden the interior machines on an individual basis as much as
	possible (large shops will have problems with this because of
	``social considerations'').

This type of setup is commonly known as a ``Screened Host Gateway,''
and is considered to be reasonably secure.  It is, of course, a
``Bastion Host'' combined with a ``Filtering Gateway'' (packet
filter).

The hardware configuration would be your router (something like a
Cisco), then a separate dedicated machine for the Application Gateway
(firewall), then your internal network.

As to whether this type of setup is overkill or not, that depends on
your attitude and considerations of company data, reputation, and time
and expense to rebuild your network in case of a breakin.

As to price, this type of system runs about $15K plus about $120 a
month for software upgrades.  (Good computer systems are like airplanes
-- they don't come cheap.)

Regards...
Fred

__
fepotts @
 fepco .
 com
http://www.fepco.com/


----- Begin Included Message -----

From: Doug Kaye <dkaye @
 rds .
 com>
Date: Fri, 13 Oct 1995 08:34:21 -0700
Subject: Re: Firewall1 Comparison -Reply

I'm seeing a lot of discussion on pack filters vs. application
gateways.  Does it make sense to implement both?  Is it too expensive
or overkill?  If you implement both, where does the filter go -- on the
public side of the application gateway?  Is it possible to run both on
the same hardware?

============================================================
Doug Kaye <dkaye @
 rds .
 com>  Rational Data Systems, Novato, CA
Tel:415-382-8400     FAX:415-382-8441     http://www.rds.com

----- End Included Message -----

Indexed By Date Previous: Re: Question: Telnet & Packet Filtering
From: markl @ glyphic . com (Mark Lentczner)
Next: Re: Firewall Questionnaire
From: frankw @ in . net (Frank Willoughby)
Indexed By Thread Previous: Re[2]: Firewall1 Comparison -Reply
From: dharris @ kcp . com (Delmer Harris)
Next: Re: Firewall1 Comparison -Reply
From: frankw @ in . net (Frank Willoughby)

Google
 
Search Internet Search www.greatcircle.com