Great Circle Associates Firewalls
(February 1996)
 

Indexed By Date: [Previous] [Next] Indexed By Thread: [Previous] [Next]

Subject: RPC through a firewall
From: RUNTERD @ MAIL . STATE . WI . US
Date: Thu, 8 Feb 1996 15:16:29 -0600
To: "firewalls(a)greatcircle.com" <firewalls @ greatcircle . com>
X400-content-type: P2-1988 (22)
X400-mts-identifier: [/PRMD=WISTGOV/ADMD=ATTMAIL/C=US/;0003800002791273000004]
X400-originator: RUNTERD @ MAIL . STATE . WI . US
X400-recipients: firewalls @ greatcircle . com

On Tuesday Feb 6,1996, Jas (Matthew K) wrote ---

<snip>.... RPC can be secured, and quite
>easily at that _if_ you know wht you are doing... punching it through
>a firewall can be difficult, but you can get RPC to do things like a)
>force it to use one and only one port, b) force it to use only TCP, c)
>turn on authentification, and fold in encryption.  <snip>
>
>***Matt
>
>p.s.  i have no qualms in saying that some of the current
>implementations of RPC servers are insecure (like NFS if not done
>with SecureNFS or with kerberos)..

This may be slightly off topic from pure firewalls discussion and I
apologize
but I may also be in a position where I will be asked to allow RPC through
a firewall. Sessions would be from a variety of platforms to a protected MVS
host.

I am able to address Matts' points A, B, and C (authentication only)
but I have come up empty in a search for _interactive_  session
encryption products that run on an MVS host.  Link level encryption
is recognized as the only current option .

Any suggestions?  Thanks all.

Bob Runte - NMB
State of Wi - Dept of Admin

Indexed By Date Previous: Re: Product selection
From: peter @ nmti . com (Peter da Silva)
Next: Re: anybody know of any vulnerabilities with "echo"
From: Michael Baumann <baumann @ proton . llumc . edu>
Indexed By Thread Previous: Re: Product selection
From: jon @ london . hcsc . com (Jon Shallow)
Next: Non-company Access ??
From: Dick_Wall @ stratus . com

Google
 
Search Internet Search www.greatcircle.com