Great Circle Associates Firewalls
(October 1997)
 

Indexed By Date: [Previous] [Next] Indexed By Thread: [Previous] [Next]

Subject: Re: To Gauntlet or not to Gauntlet
From: Frederick M Avolio <avolio @ tis . com>
Date: Mon, 13 Oct 1997 09:31:28 -0400
To: "Messano, Jim" <jim . messano @ lmco . com>, "'Firewalls Q?'" <firewalls @ greatcircle . com>
In-reply-to: <31E6F4087DC3D0119DF6006097B7704D5E3485 @ emss01tmp1 . ems . lmco .com>

We resell V-ONE's SmartGate with the Gauntlet firewall. Sounds at first
blush like that is what you need.

f

At 08:05 AM 10/10/97 -0700, Messano, Jim wrote:
>I have a customer who wants to setup a LAN for Company employees as well
>as employees of other companies, all of whom will be working together on
>a joint venture project. This LAN will be external to the Company
>Intranet. However, the customer also wants Company employees to be able
>to access the Company's Intranet. 
>
>If I insert a Gauntlet between a LAN router and a router to the Company
>Intranet, would I be able to enforce strong, two factor authentication
>(via an ACE server) and then establish a plug-gw so they could access
>all of the same services as if the Company employees were directly
>connected to the Company Intranet, without having to re-authenticate
>themselves for each service? Basically, my customer wants to
>authenticate once, then keep the "pipe" open for all intranet access.
>
>I realize that this implementation, if valid, is alien to the purpose of
>installing a Gauntlet. However, since I need to connect an external LAN
>to the Company intranet and I need to differentiate between the good
>guys and the bad guys, I thought to use the granular filtering of a
>Gauntlet. 
>
>The main purpose of the Gauntlet is to not allow non-Company employees
>to access the Intranet. (Yeah, I know I used a double negative. My
>apologies to any English majors who read this note.)
>
>Any comments/suggestions would be welcome. 
>
>

Indexed By Date Previous: Re: Firewall routing setup, Solaris 2.5.1
From: Security Mail list <firewall @ corefacts . co . uk>
Next: re: FW-1 and ICMP (lack of) statefulness
From: Bill Burns <shadow @ netscape . com>
Indexed By Thread Previous: Re: To Gauntlet or not to Gauntlet
From: "Paul D. Robertson" <proberts @ clark . net>
Next: your signature file
From: "Franco RUGGIERI" <fruggieri @ selfin . net>

Google
 
Search Internet Search www.greatcircle.com