Great Circle Associates Firewalls
(November 1997)
 

Indexed By Date: [Previous] [Next] Indexed By Thread: [Previous] [Next]

Subject: Network Address Translation Security
From: grant janssen <grantj @ pacbell . net>
Organization: Post Logic Video
Date: Tue, 25 Nov 1997 10:57:25 +0000
To: firewalls @ greatcircle . com
Reply-to: grantj @ pacbell . net

I have a Cisco router and am considering upgrading to IOS 11.2.9 and
implementing Network Address Translation.  All my ?inside? hosts are
using "unassigned" addresses (192.168.xxx.xxx). How secure will this
environment be.

More Info:
	I work for a small company with about less than fifty computers -
mostly Macs, Intel/nt [for accounting], and a few big SGI systems
[running Discreet Logic applications]. As it is, the systems requiring
Internet access have modems.  This has kept things pretty secure until
now, but the pressures from management to implement email and
internetworking for everyone are overwhelming.
	My concern about security isn?t so much about company secrets as about
my concern for one of my big systems going down from an outside attack
[getting this back up and running would likely take an entire day]. We
are a Video/Film Post Production company. Fairly unrestricted root
access is required for administration and operation in our graphics
environment.
	I looked at a couple firewall systems, but I think management will die
of sticker shock when I cut a Purchase Order for a $20,000 firewall
[it?s a lot of money for email+internet access].


Follow-Ups:
Indexed By Date Previous: Re: milkyway
From: Alfred Huger <huger @ securenetworks . com>
Next: RE: milkyway
From: David Love <dlove @ axionet . com>
Indexed By Thread Previous: IPX Conection accross untrusted network
From: "Edison E. Perez S." <eperez @ bech . cl>
Next: Re: Network Address Translation Security
From: Jesse Brown <bextreme @ pobox . com>

Google
 
Search Internet Search www.greatcircle.com