Great Circle Associates Firewalls
(November 1997)
 

Indexed By Date: [Previous] [Next] Indexed By Thread: [Previous] [Next]

Subject: IPX Conection accross untrusted network
From: "Edison E. Perez S." <eperez @ bech . cl>
Date: Tue, 25 Nov 1997 13:30:32 -0400
To: "'firewalls @ GreatCircle . COM'" <firewalls @ GreatCircle . COM>

I need connect 10 local users (as a clients) to Novell server (Novell 3.12) in the DB supplier's office accross an untrusted network. The supplier doesn't want to upgrade his Novell.

I said him, I have a firewall and I need TCP/IP conection, because security reasons.

His solutions was Novell IPTUNNEL (IPX over IP encapsulation peer to peer), but this is over UDP port 213, and my firewall haven't proxy for UDP.

And if I open the door for UDP in this conection, then other destinations can use this "security hole", or not?

Well He said me, then use packet filter with NAT (Network Address Translation), but I am not secure if I can use NAT with UDP. Is it correct?

My doubts are:

1. There are solutions for IPX/SPX encaspulation over IP/TCP, not UDP?

2. I can to put a gateway (to my cost) in the supplier's office for IPX to IP (TCP), for example Novell Intranetware 4.0?

3. Is the actual solution secure?

4. Does somebody know where I can find a solution?

Thanks,

Edison Perez 










Indexed By Date Previous: Re: milkyway
From: Frederick M Avolio <avolio @ tis . com>
Next: Re: Cisco PIX Firewall -- comments?
From: ragnar @ shr . is (Finnbogi Ragnar Ragnarsson)
Indexed By Thread Previous: [no subject]
From: target @ totcon . com (target)
Next: Network Address Translation Security
From: grant janssen <grantj @ pacbell . net>

Google
 
Search Internet Search www.greatcircle.com