Great Circle Associates Firewalls
(March 1996)
 

Indexed By Date: [Previous] [Next] Indexed By Thread: [Previous] [Next]

Subject: RE: Support of already used IP addresses
From: Alex Chircop <alex . j . chircop @ magnet . mt>
Organization: Management Systems Unit Ltd.
Date: Fri, 1 Mar 1996 12:01:13 +0100
To: firewalls @ GreatCircle . COM

You can try something like this:

------ R O U T E R ------- F I R E W A L L ------ | ---- I N T E R N E T ------------
Your intranet      Priv addr network              |
                   such as 172.16.0.0             |
                   or 10.0.0.0               Proxy Server with registered address


and configure all your clients to use the proxy server.  That way the clients will
be able to access all addresses, but are limited to the facilities available on
the proxy server.  If you use the CERN HTTPD you will have access to gopher, ftp
and http together with https if you install the SSL patch.

Hope this helps ... could others please comment on this design ?

Regards,
Alex Chircop - Admin
alex .
 j .
 chircop @
 magnet .
 mt / postmaster @
 magnet .
 mt

Management Systems Unit Ltd.
Malta - Europe

**************************************************
***  Check out http://www.magnet.mt/  ************
**************************************************



>From: Marc Rapoport <rapoport @
 iway .
 fr>
>Date: Thu, 29 Feb 1996 16:29:49 +0100
>Subject: Support of already used IP adresses

>Hi, our private Intranet adressing plan is using several class B that are
>already
>allocated on the Internet, as our Intranet was created long before we
>planned to interconnect
>with the Internet.
>We use a single firewall which masks our private adresses, but we are not
>able to reach
> the public portion of the Internet that uses the same IP adresses.
>The only solution i know to handle that problem is to use 2 firewalls
>serialized 
>with a pseudo network between the Intranet and the Internet.
>Does anybody knows a product able to solve this problem with only one firewall ?
>Thanks in advance.

>=========================================================================
>öö      Marc Rapoport :      rapoport @
 iway .
 fr                          öö
>öö      AGF.SI Tour Franklin - La Defense 8                            öö
>öö      92042 PARIS LA DEFENSE CEDEX                                   öö
>öö      Tel : 49.03.31.77 Fax : 47.67.07.90                            öö
>=========================================================================

Indexed By Date Previous: FW: rx but no tx wiring for ethernet
From: "Anthony.W.Youngman" <Wally @ ecaltd . com>
Next: Re: IP fragments and packet filters
From: "Eric V. Smith" <EricSmith @ windsor . com>
Indexed By Thread Previous: Re: rx but no tx wiring for ethernet
From: Howard Barnett <HBarnettt @ FastLane . NET>
Next: RE: Support of already used IP addresses
From: "Palmer, John" <JPALME @ dwpcpo1 . dreamworks . com>

Google
 
Search Internet Search www.greatcircle.com