Great Circle Associates Firewalls
(October 1996)
 

Indexed By Date: [Previous] [Next] Indexed By Thread: [Previous] [Next]

Subject: Re: Gauntlet vs. Sidewinder
From: Joav Kohn <joav . kohn @ us . landisstaefa . com>
Date: Thu, 03 Oct 1996 07:06:32 -0500 (CDT)
To: firewalls-owner <firewalls-owner @ GreatCircle . COM>, jeromie <jeromie @ garrison . com>, "david.helms" <david . helms @ checkpoint . com>
Cc: firewalls <firewalls @ GreatCircle . COM>
Autoforwarded: false
Disclose-recipients: prohibited
Hop-count: 2
Importance: normal
In-reply-to: <9610030326 . AA03445 @ ukn0 . garrison . com>
Mr-received: by mta PFMSV1.MUAS; Relayed; Thu, 03 Oct 1996 07:06:32 -0500
Mr-received: by mta PFMSV1; Relayed; Thu, 03 Oct 1996 07:06:32 -0500
Mr-received: by mta PFMMRX; Relayed; Thu, 03 Oct 1996 07:07:59 -0500
Sensitivity: Company-Confidential
Ua-content-id: 11AA19C61F00
X400-mts-identifier: [;2432060703101996/A00383/PFMSV1]

> 	1) People generally have their SMTP server sitting somewhere within
> the "[Internal Net]".  The firewall would say something like "We only allow
> connections to port 25 of the SMTP gateway".  If the SMTP gateway is sitting
> inside, the perimiter is broken.
> 

The proper way to set this up is to have the firewall itself accept mail with
smapd and sendmail v8.6 and then re-route that mail to the internal servers.
The internal servers are never vulnerable to an attack because the outside
world cannot talk directly to them. 

>
> 	2) If the internet SMTP gateway sits on the DMZ, and the customer
> has several internal SMTP gateways that distribute all the mail, then again,
> the SMTP gateway on the DMZ would have access to send data to the inside SMTP
> hosts, thus providing information flow.  If the internal SMTP gateways are
> vulerable to attack (IE: version of sendmail that have problems, IE: ALL)
then
> again, the perimiter is broken.
> 

The best way to secure things is to assume nothing is secure on your internal
network. Reduce your points of faliure on the DMZ, and trust nothing. If you
make sure that your DMZ versions of sendmail are secure and they talk to your
internal servers, no direct communication ever takes place from the external
network to the internal network.

-joav


Indexed By Date Previous: RE: NT Security
From: Petri Virkkula <pvirkkul @ iki . fi>
Next: Re: ifconfig
From: James R Grinter <jrg @ gbnet . net>
Indexed By Thread Previous: RE: Gauntlet vs. Sidewinder
From: rabbi @ www . valuu . net (Rabbi Haim Cassorla)
Next: Re: Gauntlet vs. Sidewinder
From: jeromie @ garrison . com (Hmm)

Google
 
Search Internet Search www.greatcircle.com