Great Circle Associates Firewalls
(February 1997)
 

Indexed By Date: [Previous] [Next] Indexed By Thread: [Previous] [Next]

Subject: Re: Split DNS - Another way
From: "Marcus J. Ranum" <mjr @ clark . net>
Organization: V-ONE Corp Baltimore office
Date: Wed, 12 Feb 1997 22:18:48 +0000
To: firewalls @ GreatCircle . COM
Cc: mjr @ clark . net
Comments: Authenticated sender is <mjr @ mail . clark . net . >
Reply-to: mjr @ clark . net

> I have been watching the split DNS discussions and learned a lot of
> the issues, good and bad, for implementing such.

I think a good approach is to turn the problem on its head. What
most folks implement with "split DNS" is actually "split reFrom firewalls-owner  Wed Feb 12 22:50:52 1997
Received: (majordom @
 localhost) by miles.greatcircle.com (8.8.5/Lists-960417-1) id WAA11476 for firewalls-outgoing; Wed, 12 Feb 1997 22:41:33 -0800 (PST)
Received: from lhr.aster.com.pk (lhr.aster.com.pk [203.128.6.8]) by miles.greatcircle.com (8.8.5/Miles-960830-1) with SMTP id WAA11440 for <firewalls @
 greatcircle .
 com>; Wed, 12 Feb 1997 22:40:47 -0800 (PST)
Received: by lhr.aster.com.pk (Smail3.1.28.1 #4)
	id m0vuuqO-0004HfC; Thu, 13 Feb 97 11:40 GMT+0500
Date: Thu, 13 Feb 1997 11:40:32 +0500 (GMT+0500)
From: Rafeeq Ur Rehman <rehman @
 lhr .
 aster .
 com .
 pk>
To: Jim McKenzie <jmckenze @
 ncfcomm .
 com>
cc: firewalls @
 greatcircle .
 com
Subject: Re: What firewall do I need.
In-Reply-To: <199702130426 .
 WAA19658 @
 cereal .
 ncfcomm .
 com>
Message-ID: <Pine .
 LNX .
 3 .
 91 .
 970213113910 .
 658D-100000 @
 lhr .
 aster .
 com .
 pk>
MIME-Version: 1.0
Content-Type: TEXT/PLAIN; charset=US-ASCII
Sender: firewalls-owner @
 GreatCircle .
 COM
Precedence: bulk

On Wed, 12 Feb 1997, Jim McKenzie wrote:

> I am about to hook our 130 PC lan running WFW, WIN95, & NT to a dedicated
> internet connection.  What is my risk to hackers, etc. when we make this
> connection, what is the best firewall to use with the least setup and
> administrative work.
> 
I am using FWTK on Linux in such a network with SUN, SCO Unix, and 
Ultrix. I have found it good against test attacks. The LAN is on Internet 
and running smoothly.

Rafeeq Ur Rehman
rehman @
 lhr .
 aster .
 com .
 pk




Follow-Ups:
Indexed By Date Previous: Re: Spit DNS - Another way
From: Jerry Mendes <mendes @ garnet . berkeley . edu>
Next: Re: strange behavior
From: Rafeeq Ur Rehman <rehman @ lhr . aster . com . pk>
Indexed By Thread Previous: Re: Mirror of NT Exploits
From: "Gregg Earnhart" <ge @ gte . net>
Next: Re: Split DNS - Another way
From: Dana Bourgeois <fg @ portal . com>

Google
 
Search Internet Search www.greatcircle.com