Great Circle Associates Firewalls
(August 1994)
 

Indexed By Date: [Previous] [Next] Indexed By Thread: [Previous] [Next]

Subject: Re: conditional encryption
From: shibumi @ cisco . com (Kenton A. Hoover)
Date: Tue, 23 Aug 1994 09:57:52 -0700
To: Shannon Bell <shan . bell @ sware . com>, firewalls @ GreatCircle . COM

At 12:13 18/08/94, Shannon Bell wrote:
>I want to set up my system to use encrypted links to specified sites and
>unencrypted links to the general public. Currently the plan for our network
>looks like:
>
>Internet --- Firewall --- router === various subnets
>
>It seems to me that all I really need is a way to have inetd pick which of
>2 ftpds (or telnetds or rloginds) to call based on ip number of the remote
>host. Does anyone know of a package that does this?


My version of the solution to this problem looked like this:

                       +------------+       +-----------+
internal nets ---------|   router   |-------|   router  |-------- Internet
                       +------------+       +-----------+
                              |                   |
                       +------------+             |
                       | IP ncryptor|-------------+
                       +------------+


The routers need to be programmed to route packets from / to the clean nets
as appropriate.   You might be able to do this with raw streams and stream
encryptor/decryptor units, given some clever thinking an a limited set of
key streams.


| Kenton A. Hoover        Senior Systems Administrator |  shibumi @
 cisco .
 com |
| Engineering Computer Services                        |                    |
| Cisco Systems, Inc.                                  |    +1 415 324 5249 |
|===========================================================================|
|  "I remember a time in the wilds of Afganistan.  We lost our corkscrew.   |
|   We were forced to live on food and water for many days" -- W.C. Fields  |



Indexed By Date Previous: FW: Firewall routers
From: "Vegsund, Richard" <MISRHV @ infosvcs . tmh . tmc . edu>
Next: Head above parapet
From: Peter @ infotek . demon . co . uk (Peter M White)
Indexed By Thread Previous: Re: conditional encryption
From: snyderra @ dunx1 . ocs . drexel . edu (Bob Snyder)
Next: Re: conditional encryption
From: snyderra @ dunx1 . ocs . drexel . edu (Bob Snyder)

Google
 
Search Internet Search www.greatcircle.com