Great Circle Associates Firewalls
(March 1993)
 

Indexed By Date: [Previous] [Next] Indexed By Thread: [Previous] [Next]

Subject: Re: Firewalls and NFS
From: chk @ alias . com (C. Harald Koch)
Date: Tue, 23 Mar 1993 09:56:36 -0500
To: firewalls @ GreatCircle . COM

Someone mentioned UUNET's DES box. I asked them for info, and received
permission to publish it, so here it is. I apologize to any of you who think
this is commercialism; *I* think it's relevant to the list.

----- Cut Here -----

UUNET Lan Guardian (TM) 

Secure Connectivity over Public Internets


Introducing the Lan Guardian

The UUNET Lan Guardian is the first in a family of network 
security products from UUNET Technologies, Inc., of 
Falls Church, VA. The Lan Guardian is a hardware security 
solution designed for companies that wish to benefit from 
the cost savings of using Commercial Internet Service 
providers (such as UUNET's AlterNet IP service) but are 
concerned about the security of their confidential data 
once it leaves their facility.

What does it do?

The Lan Guardian addresses those concerns by "splicing" 
into the connection between the company's Ethernet and 
external router and encrypting all data sent between company 
networks, while also (optionally) allowing connections to 
non-company facilities to continue without encryption. 
Operation of the Lan Guardian is totally transparent to 
network users and is simple for network administrators to 
manage. Full configuration support is provided.

The Lan Guardian selectively encrypts or decrypts each packet 
based on the information in the packet header. Only the data 
portion of the packet is encrypted, thereby allowing the packet 
to be transmitted with normal routers. The Lan Guardian may 
also be configured to block selected or all external traffic 
as well as to use a different key for each network.

By using fast processors and hardware encryption chips, the 
Lan Guardian can encrypt/decrypt while only adding less than 
a millisecond of delay. It is imperceptible to the network's 
users, while providing peace of mind to the network's managers.

Using the Lan Guardian eliminates the concern that all users 
are running the appropriate application packages and using 
the appropriate level of security when sending sensitive 
company data outside the company facilities. The Lan Guardian 
ensures that company proprietary data sent to remote offices 
is never in the clear. This allows companies to exchange 
sensitive financial data or business plans with their remote 
offices via a Commercial Internet Service provider without fear 
that the data will be compromised.

How does it work?

Functionally, the Lan Guardian is a 50 MHz Motorola 68040, 
with Dual Intel 82596CA Ethernet Processors, a CEI 99C003 Super Crypt 
High Speed Encryption Chip and 4 - 32 Megabytes of Main Memory.

Keys are exchanged out of band via either a serial port or a 
floppy disk. Support for Public Key based key distribution is 
being added.

What's next?

Optional "firewall" and other functionality will be available 
later this year. Additional models including T-1 speed serial 
interfaces will be available soon.

How can I get a Lan Guardian?

Existing AlterNet customers may purchase the Lan Guardian now 
for US$6,000 or optionally lease for $500/month. The Lan Guardian 
carries a one year hardware and software warranty.


UUNET Technologies, Inc.
3110 Fairview Park Drive, Suite 570
Falls Church, Virginia 22042 USA
+1 800 4UUNET3 (voice)
+1 703 204 8000 (voice)
+1 703 204 8001 (fax)
alternet-info @
 uunet .
 uu .
 net

930310

-- 
Minda Seagroves				mks @
 uunet .
 uu .
 net
(703-204-8000)				uunet!mks

----- Cut Here -----

-- 
Main's Law: For every       | C. Harald Koch  Alias Research, Inc. Toronto, ON
action, there is an equal   | chk @
 alias .
 com                (work-related mail)
and opposite goverment      | chk @
 gpu .
 utcs .
 utoronto .
 ca     (permanent address)
program.                    | VE3TLA @
 VE3OY .
 #SCON .
 ON .
 CA .
 NA            (AMPRNet)


Indexed By Date Previous: Re: Firewalls and NFS -
From: smb @ research . att . com
Next: Re: Firewalls and NFS
From: Claire Durocher <durocher @ ll . mit . edu>
Indexed By Thread Previous: Re: Firewalls and NFS
From: Brent Chapman <brent @ GreatCircle . COM>
Next: Re: Firewalls and NFS
From: Claire Durocher <durocher @ ll . mit . edu>

Google
 
Search Internet Search www.greatcircle.com