Great Circle Associates Firewalls
(July 1996)
 

Indexed By Date: [Previous] [Next] Indexed By Thread: [Previous] [Next]

Subject: Re: Protecting our INTRANETS
From: Adam Shostack <adam @ homeport . org>
Date: Wed, 24 Jul 1996 20:53:45 -0500 (EST)
To: michael @ memra . com (Michael Dillon)
Cc: firewalls @ GreatCircle . COM
In-reply-to: <Pine . BSI . 3 . 93 . 960724111718 . 13644I-100000 @ sidhe . memra . com> from "Michael Dillon" at Jul 24, 96 11:21:18 am

Port 70 is assigned to gopher (is gopher still out there?)

Use of port 8000, 8080, or 8888 all have the benefit of being
unprivledged ports, and thus, you don't need your web server to be
running as root.

Adam


Michael Dillon wrote:

| So you install a firewall between the two networks and block everything
| except port 25 for email and....
| 
| > My problems is http.
| 
| port 70 for http. Make sure that nobody runs a web server on the corporate
| network using anything other than port 80. Then set up one web server to
| run on port 70 (normally used for gopher) and place things that the
| dirty network is allowed to see on there. Any web servers within the dirty
| network will still work fine as well. If you need to let the corporate
| side see certain things on the dirty side then set up another web server
| using port 70 on the dirty side.
| 
| Michael Dillon                   -               ISP & Internet Consulting
| Memra Software Inc.              -                  Fax: +1-604-546-3049
| http://www.memra.com             -               E-mail: michael @
 memra .
 com
| 


-- 
"It is seldom that liberty of any kind is lost all at once."
					               -Hume



Follow-Ups:
References:
Indexed By Date Previous: Re: apache-httpd 1.1 and fwtk http-gw
From: Bradley Rosser <brad @ pinerivers . qld . gov . au>
Next: Re: firewall-1: Number of Interfaces
From: bjc @ nscatc . JPL . NASA . GOV (BJ Chippindale)
Indexed By Thread Previous: Re: Protecting our INTRANETS
From: Michael Dillon <michael @ memra . com>
Next: Re: Protecting our INTRANETS
From: Michael Dillon <michael @ memra . com>

Google
 
Search Internet Search www.greatcircle.com