Great Circle Associates Firewalls
(October 1997)
 

Indexed By Date: [Previous] [Next] Indexed By Thread: [Previous] [Next]

Subject: Re: Firewall beliefs T/F ?
From: Vin McLellan <vin @ shore . net>
Date: Tue, 28 Oct 1997 09:40:59 -0500
To: firewalls @ greatcircle . com
Cc: akhila @ cc . iitd . ernet . in
In-reply-to: <9710280445 . AA23896 @ surya . iitd . ernet . in>

	Akhila  Sinha <akhila @
 cc .
 iitd .
 ernet .
 in> sketched a proposed
intranet/extranet architecture:

>We are looking at firewall solutions to connect a 2MB link to about 2500
>users.... <snip>

>     full tcp inward from selected machines outside
>     Internet web, Intranet Web.... <snip>

>     The News and Internet Web servers should not be on the secure side
>     (What are other problems beside errant CGI  programs ?)

	Inside and out, you likely need strong user authentication (X509
certs and smartcards, or two-factor authenticators: hand-held tokens or
software token-emulators) & (at least) external crypto (PKI or VPNs.)

	Suerte,
		_Vin


"Cryptography is like literacy in the Dark Ages. Infinitely potent, for
good and ill... yet basically an intellectual construct, an idea, which by
its nature will resist efforts to restrict it to bureaucrats and others who
deem only themselves worthy of such Privilege."
_ A thinking man's Creed for Crypto/ vbm.

 *     Vin McLellan + The Privacy Guild + <vin @
 shore .
 net>    *
  53 Nichols St., Chelsea, MA 02150 USA <617> 884-5548




References:
Indexed By Date Previous: Newbie Question
From: XXxFeaRxXx @ aol . com
Next: Re: Comments please
From: epage @ bhcpns . org
Indexed By Thread Previous: Re: Firewall beliefs T/F ?
From: Badri Pillai <Badri . Pillai @ ecrc . de>
Next: Advertisement: "Fish Lovers Only"
From: tri-max @ t-1net . com

Google
 
Search Internet Search www.greatcircle.com