Great Circle Associates Firewalls
(February 1996)
 

Indexed By Date: [Previous] [Next] Indexed By Thread: [Previous] [Next]

Subject: Re: User level firewall / proxy authentication
From: zuhn @ sctc . com (david d `zoo' zuhn)
Organization: Secure Computing Corporation; Roseville, MN
Date: Wed, 07 Feb 1996 09:11:48 -0600
To: firewalls @ greatcircle . com
References: <3117F7B3 . 3647 @ mecx05 . colesmyer . com . au> <Pine . SUN . 3 . 91 . 960206184019 . 1684D-100000 @ parka . winternet . com>

// > Are there any firewall or proxy server products available that will allow 
// > outgoing user authentication based upon a user id, rather than an IP 
// > address?
// > 
// > Our users are mobile and this makes it difficult to restrict internet 
// > access on a per user basis, since their source IP address is likely to
// > change.
// 
// This sounds pretty unsafe!  How do you prevent me from spoofing one of 
// your users?

Yes, there are several firewall systems that handle authentication on a
per-user basis.  All that I know of will also allow permission acl's that
include host address ranges as well.  This can be useful when dealing with
a range of dynamic addresses (such as allocated by DHCP or similar
protocols), requiring userid based authentication for those addresses, and
relying on host-based permissions for the static addresses on the network.

As for the safety, there are usually a variety of means available for user
authentication.  Those I have seen in the market range from insecure
username & reusable passwords (a la Unix passwords) to software based
challenge-response systems (LOCKout or S/Key) to hardware based token
cards of some form or another (SecurID, SNK).  A common tradeoff in
authentication systems is price vs. unspoofability.

For many sites, outbound authentication is used more for accounting
chargeback schemes than for any more stringent authorization, so a
reusable password system isn't unreasonable.  But I'd never trust inbound
authentication to anything that doesn't use some form of cryptographically
secure algorithm.

-- 
david d `zoo' zuhn   ---  secure computing corporation
zuhn @
 sctc .
 com 


References:
Indexed By Date Previous: Re: Need a few pointers
From: Mohammed Ali <ali @ protosoft . com>
Next: Most Secure Unix?
From: don_tompkins @ esd . tracor . com
Indexed By Thread Previous: Re: User level firewall / proxy authentication
From: Ron DuFresne <dufresne @ winternet . com>
Next: Re: User level firewall / proxy authentication
From: Bob Bosen <bbosen @ netcom . com>

Google
 
Search Internet Search www.greatcircle.com