Great Circle Associates Firewalls
(December 1995)
 

Indexed By Date: [Previous] [Next] Indexed By Thread: [Previous] [Next]

Subject: Re: Firewall-1, any hints or gotcha's in it's installation??
From: Craig Anderson <craiga @ Ipsilon . COM>
Date: Thu, 21 Dec 1995 12:19:44 -0800
To: Brain21 <brain21 @ montag33 . residence . gatech . edu>
Cc: Craig Anderson <craiga @ Ipsilon . COM>, Firewalls @ GreatCircle . COM
In-reply-to: Your message of "Thu, 21 Dec 1995 10:38:31 EST." <Pine . LNX . 3 . 91 . 951221103457 . 23143B-100000 @ montag33 . residence . gatech . edu>

> On Wed, 20 Dec 1995, Craig Anderson wrote:
> 
> > > 	Don't forget to harden the underlying OS before installing, a
> > > point which the manual makes no mention of.  I've seen FW-1s running
> 
> > I say that this is not necessary.  If you set up your filters
> > correctly, then Solaris will never see any packets it's not
> > supposed to since the filters operate between the ethernet
> 
> Uhh. Wait a minute.  Are you running sendmail?  and ftp server?  Then you 
> should.  What about someone who decides to tunnel past your firewall and 
> launches an IP w/i IP attack, esp. w/ UDP?  What about someone from 
> inside who wants to gain root?  Your firewall can be your best defense, 
> but theres always a way around one if you know your stuff (at least 
> that's the approach that I take)...
> 
> Brain21

If you don't allow any packets to land on the firewall (all services
are provided by other machines on the DMZ) then there is no risk to
the firewall itself.  The DMZ machines are at risk, but they are in
captivity and can't get too far.  But I don't let packets land on
the firewall from either inside or out; it only routes within the
constraints of the filters.

Craig



Follow-Ups:
References:
Indexed By Date Previous: Re: Session hijacking?
From: Brain21 <brain21 @ montag33 . residence . gatech . edu>
Next: Re: Proxy v. Packet Filter
From: bobk @ manzanita . DEV . 3Com . COM (Bob Konigsberg)
Indexed By Thread Previous: Re: Firewall-1, any hints or gotcha's in it's installation?? y/n) y mailbox Delete message(s)? (
From: "Keith L. Wong" <keithw @ tp . com>
Next: Re: Firewall-1, any hints or gotcha's in it's installation??
From: Brain21 <brain21 @ montag33 . residence . gatech . edu>

Google
 
Search Internet Search www.greatcircle.com