Great Circle Associates Firewalls
(January 1997)
 

Indexed By Date: [Previous] [Next] Indexed By Thread: [Previous] [Next]

Subject: Re: security risks of accessing internal hosts from the 'Net
From: larry <larry @ ca . cch . com>
Date: Tue, 21 Jan 1997 07:29:11 -0500 (EST)
To: mjo @ dojo . mi . org
Cc: firewalls @ greatcircle . com

| From firewalls-owner @
 greatcircle .
 com  Mon Jan 20 21:20:59 1997
| Date: Mon, 20 Jan 1997 19:37:49 -0500 (EST)
| To: larry @
 ca .
 cch .
 com (larry)
| That may or may not be the case.  Depends on your application.  What
| specifically do you want to do?  Your first task will be to define that,
| so everyone is clear on what's going on.
| Depending on how they "access" a server behind your firewall, that may or
| may not be fine.  Consider email, for example -- lots of people "allow"
| Internet email to go through a firewall to some internal server scheme.
| Realize that there may be an acceptable tradeoff between security and
| functionality (or there may not be).  

  the application in question is web based, so users on the 'Net would
  access a web server on our LAN ( behind the firewall ), so we're
  talking about interactive access as opposed to non-interactive ( mail ).


  <stuff deleted>

| After you figure out what you want to do, then you have to figure out if
| you can architect your service in a sane and effective manner.  If you
| can, great.  If not, don't.  

   I have already determined that I cannot do what is being asked in a
   "sane" manner ie: a manner that will allow me to go home and sleep
   at night. However management always wants copious documentation to
   back up even the simplest assertions, hence my posting to the list.

   If you have any info to support the position I alluded to in the
   original message I would appreciate hearing from you.


Tue Jan 21 07:28:38 EST 1997
=====================================================================
Larry Chin {Larry_Chin @
 ca .
 cch .
 com}	CCH Canadian Ltd.
Phone: 416-441-4001 ext. 349		6 Garamond Court
Fax:   416-441-3544			North York, Ontario, M3C 1Z5
=====================================================================

"Wagner's music is better than it sounds."
		-- Mark Twain


Follow-Ups:
Indexed By Date Previous: Strange Error loading Solstice Firewall
From: "Alessandro Jannuzzi" <cs84088 @ pop1 . csn . com . br>
Next: Re[2]: TCP/IP encrypted connection
From: Gregory . Hull @ fdc-invest . com (Gregory Hull)
Indexed By Thread Previous: Re: security risks of accessing internal hosts from the 'Net
From: "Mike O'Connor" <mjo @ dojo . mi . org>
Next: Re: security risks of accessing internal hosts from the 'Net
From: Adam Shostack <adam @ homeport . org>

Google
 
Search Internet Search www.greatcircle.com