Great Circle Associates Firewalls
(January 1996)
 

Indexed By Date: [Previous] [Next] Indexed By Thread: [Previous] [Next]

Subject: Re: Firewalls and bastion hosts
From: Chris Woods <cjwoods @ paladin . com>
Date: Wed, 17 Jan 1996 20:20:56 -0500 (EST)
To: "Steven K. Sharp" <sksharp @ cts . com>
Cc: Firewalls @ GreatCircle . COM
In-reply-to: <m0tcgEc-000UzgC @ mailhub . cts . com>

On Wed, 17 Jan 1996, Steven K. Sharp wrote:

> Our company is going to be going to be getting one of the dual ethernet
> routers and I'm wondering if we still need a bastion host.  One net will be
> the "secure" net and one open to the unwashed masses; of what use is the
> bastion host?  Is FWTK is similar still needed?  Obviously we want to be
> secure, but with this setup what does the bastion host provide?  Any help or
> references are appreciated.

The bastion host serves basically as a stripped-down machine that runs
services that you may want to provide to the Internet (incoming WWW, FTP,
etc.), as well as providing a (more) secure method by which to retrieve
and forward email that is meant for people on your green (internal)
network. Also, the bastion host, if running a half-decent firewall
package, will most likely have better logging and auditing capabilities
than any router. 

This is basically the concept of a "perimeter network". The external
router allows direct connections from the Internet to the hosts on the
perimeter network, while the internal router allows connections from your
internal network to the hosts and servers on the perimeter network. 

    Chris Woods				Systems Administrator
    cjwoods @
 paladin .
 com	 (office)	Paladin Computing Solutions
    cjwoods @
 gigotech .
 net (home)		http://www.paladin.com
    "A computer without Windows is like a fish without a bicycle."



References:
Indexed By Date Previous: Re: Firewall in an ATM environment
From: lacey @ dsea . com (Dan Lacey)
Next: Electronic Commerce
From: Ravi Kalakota <kalakota @ uhura . cc . rochester . edu>
Indexed By Thread Previous: Firewalls and bastion hosts
From: "Steven K. Sharp" <sksharp @ cts . com>
Next: Electronic Commerce
From: Ravi Kalakota <kalakota @ uhura . cc . rochester . edu>

Google
 
Search Internet Search www.greatcircle.com