Great Circle Associates Firewalls
(December 1995)
 

Indexed By Date: [Previous] [Next] Indexed By Thread: [Previous] [Next]

Subject: Re: TokenRing Firewalls
From: Darren Reed <avalon @ coombs . anu . edu . au>
Date: Sat, 9 Dec 1995 14:24:54 +1100 (EDT)
To: Paul @ cheops . anu . edu . au, Ferguson @ cheops . anu . edu . au, <pferguso @ cisco . com>
Cc: Firewalls @ GreatCircle . COM (Firewalls Mailing List)
In-reply-to: <Pine . SOL . 3 . 91 . 951208082108 . 223A-100000 @ services> from "Frank K. Senter" at Dec 8, 95 08:34:51 am

I wrote:
> The link layer (Token Ring/Ethernet/PPP) should not make any >difference to
> your firewall.  If you go for the proxy firewall, it makes 0 difference,
> only some packet filter types might have trouble if they've only been
> implemented to support Ethernet frames.  ie it won't be of concern to your
> ciscos if you include them as part of your firewall.

Paul Ferguson wrote:
> However, if its *routed* and not bridged, it becomes much more of a
> palatable exercise to filter traffic. I would also suggest that access
> control at layer 3 is much less CPU intensive than at layer 2. To 
> generically state that 'it won't be of concern' is the Wrong Thing.

I was refering to it (link layer) not making any difference to ip access
list writing, extended or not, for firewalling.  You should still be
dropping all incoming packets, except for a few you want to allow
through.  I was assuming that the cisco would enable you to write such
access lists without needing to worry, too much, about whether routing
or bridging is done...(assuming you're not bridging your token ring to
the internet O:)

darren


References:
Indexed By Date Previous: Re: is a second filter router worthwhile?
From: Rik Harris <Rik . Harris @ fulcrum . com . au>
Next: NT Bulkheads
From: "A. Padgett Peterson, P.E. Information Security" <PADGETT @ hobbes . orl . mmc . com>
Indexed By Thread Previous: Re: TokenRing Firewalls
From: "Frank K. Senter" <fsenter @ mail . state . mo . us>
Next: Re: TokenRing Firewalls
From: Paul Ferguson <pferguso @ cisco . com>

Google
 
Search Internet Search www.greatcircle.com