Great Circle Associates Firewalls
(February 1995)
 

Indexed By Date: [Previous] [Next] Indexed By Thread: [Previous] [Next]

Subject: Re: Test labs
From: "Simon J. Gerraty" <sjg @ zen . void . oz . au>
Date: Thu, 02 Feb 1995 00:05:00 +1100
To: padgett @ tccslr . dnet . mmc . com (A. Padgett Peterson, P.E. Information Security)
Cc: firewalls @ greatcircle . com
In-reply-to: Your message of "Tue, 31 Jan 95 19:35:38 CDT." <9502010035 . AA06263 @ uvs1 . orl . mmc . com>

> sjg rites:
> >What's wrong with setting up your firewall in a test lab?  I mean the
> >entire DMZ,choke etc etc.  You can then test it until you are happy
> >before letting others have a go...
> 
> Oh I agree, now everyone out there whose organization *has* a dedicated 

That's just it though.  You don't need a "test lab".  You need a
couple of desks (well, actually I just setup several machines stacked
one atop the other :-) and a few power boards.  Ok, the power boards
are usually the biggest problem... more than once I've had to nip out
to Tandy (or whatever...)

Presumably you already have the bastion host(s) and router(s) that you
plan to put into the firewall.  Now just set it all up but _don't_
connect it to either the internet or the internal net - tempting as
that might be... 

The only real extra resources needed are the two (or more) systems
needed to simulate your attackers and the prize (internal net).  Most
companies can scrounge a couple of 386's to run NetBSD or whatever for
this...

When you are done testing, just plug in the other networks.

--sjg

Next week we'll explain how to build box girder bridges and how to play
the flute...
		Monty Python

Indexed By Date Previous: Dangerous Proxy (Was: benefit of proxy-server )
From: Rens Troost <rens @ imsi . com>
Next: Security Training
From: sjoffri @ SJOFFRI . DOA . STATE . LA . US
Indexed By Thread Previous: Re: Test labs
From: Rick Smith <smith @ sctc . com>
Next: Re: Test labs
From: mjs @ tiaa . org (marty shannon)

Google
 
Search Internet Search www.greatcircle.com