Great Circle Associates Firewalls
(October 1997)
 

Indexed By Date: [Previous] [Next] Indexed By Thread: [Previous] [Next]

Subject: Re: Using DHCP with Firewalls
From: Bernd Eckenfels <lists @ lina . inka . de>
Date: Fri, 24 Oct 1997 00:57:37 +0200
To: Anton J Aylward <anton @ Toronto . com>
Cc: "(* Unknown *)" <phoenix @ clark . net>, firewalls @ greatcircle . com
In-reply-to: <3 . 0 . 32 . 19971023102751 . 007c16b0 @ mail . the-wire . com>; from Anton J Aylward on Thu, Oct 23, 1997 at 10:33:21AM -0400
References: <3 . 0 . 32 . 19971023102751 . 007c16b0 @ mail . the-wire . com>

Hello,

> Of you're a 85 person shop with a 100 user licence why 
> are you using DCHP in the first place?  Why aren't you using
> static assignment?  'Cos you want to play with nifty toys?

Cause its a hell lot of work to keep an ip table with static addresses up to
date. Its not a technical Problem, its a problemwith users :)

> Suppose you have a single user license.
> I do a FTP thru the firewall.  While I'm in that session, you
> can't go thru.  I finish my ftp and log out.  Now you can do your
> telnet.  Now multiply by 50, or 100......

Or use a WWW Browser which tries to build 6 connections at the same time
(and add another 10connections in any of those nasty timeout states of TCP
which may last for 10minutes). Hmm.. seems to me that you have to allow
20sessions for each user :)

Greetings
Bernd
-- 
  (OO)      -- Bernd_Eckenfels @
 Wittumstrasse13 .
 76646Bruchsal .
 de --
 ( .. )  ecki @
 {inka .
 de,linux.de,debian.org} http://home.pages.de/~eckes/
  o--o     *plush*  2048/93600EFD  eckes @
 irc  +4972573817  BE5-RIPE
(O____O)       If privacy is outlawed only Outlaws have privacy


References:
Indexed By Date Previous: Re: sex,lies, and application proxy based fw vs Check Point
From: Frederick M Avolio <avolio @ tis . com>
Next: Re: suggestion
From: Gordy Thompson <gordy @ nytimes . com>
Indexed By Thread Previous: Re: Using DHCP with Firewalls
From: Peter da Silva <peter @ baileynm . com>
Next: RE: Using DHCP with Firewalls
From: "Stackpole, Bill" <BSTACKPO @ sla . com>

Google
 
Search Internet Search www.greatcircle.com