Great Circle Associates Firewalls
(November 1995)
 

Indexed By Date: [Previous] [Next] Indexed By Thread: [Previous] [Next]

Subject: Re: Vendor Product Access
From: bobk @ manzanita . DEV . 3Com . COM (Bob Konigsberg)
Date: Tue, 14 Nov 95 08:27:08 PST
To: TMOONEY @ umi . com
Cc: firewalls @ greatcircle . com

It's a BAD idea.  What I'd recommend (based on experience) is to set up
a separate access for vendors (Frame Relay, ISDN, whatever), and run them
through a firewall (a filtering router will work in this case).  Also,
you need to get a LOT more specific about the specific types of traffic
that you will allow through.  Don't let the vendor bamboozle your management
into believing that this type of wide open access is "necessary" to the
proper operation of whatever service they are providing.

I will usually allow either a subnet of a vendor, or we assign an IP address
that we specify for them to use by PPP or CSLIP which gives us more precise
control over what they are doing, and where they can connect to within our
network.

Good luck,

BobK


Indexed By Date Previous: Re: Configuration
From: sgcccdc @ citec . qld . gov . au (Colin Campbell)
Next: Re: NTP through a firewall
From: Thomas E Zerucha <zerucha @ shell . portal . com>
Indexed By Thread Previous: Re: Vendor Product Access
From: "Mike O'Connor" <mjo @ dojo . mi . org>
Next: Re: Vendor Product Access
From: daemeonr @ Anthros . Com@Anthros.Com

Google
 
Search Internet Search www.greatcircle.com