Great Circle Associates Firewalls
(July 1997)
 

Indexed By Date: [Previous] [Next] Indexed By Thread: [Previous] [Next]

Subject: Re: Firewalls-Digest V6 #351
From: Bill Heiser <bill @ bh . org>
Date: Thu, 24 Jul 1997 06:53:51 -0400
To: Firewalls @ GreatCircle . COM
References: <199707240800 . BAA07746 @ honor . greatcircle . com>

> Bottom line is that if you are considering doing NT to NT work at all
> (inter-domain stuff, administration, etc...) through a Firewall, it
> makes far more sense to do that within a PPTP tunnel than not because
> its a seemless connection that allows full MS Networking connectivity
> without a lot of kludging.

If you are allowing PPTP tunnelling thru the firewall to the PPTP
server,with that providing access to internal hosts, how is that
different than
multi-homing the PPTP server inside/outside?  Are you thinking in terms
of protecting the PPTP server from "network level attacks" on the
Internet?
Either way, however, it seems the PPTP server is part of the "security
perimeter".    Or in the paragraph above are you implying that the FW
would allow very restricted access to the PPTP server, eg doing the
PPTP tunnelling in conjunction with a FW user authentication scheme?
Hmmmm, PPTP within SecuRemote?  :-)



--
Bill Heiser
mailto:bill @
 bh .
 org
http://www.bh.org



Indexed By Date Previous: Mailing list
From: "Gönc, Timur" <tim . gonc @ telenordia . se>
Next: RE: summary: firewalls and B2
From: Tim Shoemaker <tshoemaker @ normandev . com>
Indexed By Thread Previous: Mailing list
From: "Gönc, Timur" <tim . gonc @ telenordia . se>
Next: standard policy on fw-1
From: Swee-Chuan Khoo <sckhoo @ asiapac . net>

Google
 
Search Internet Search www.greatcircle.com