Great Circle Associates Firewalls
(March 1995)
 

Indexed By Date: [Previous] [Next] Indexed By Thread: [Previous] [Next]

Subject: Re: Firewall-to-Firewall Encryption
From: "william.wells" <william . wells @ damark . com>
Date: Wed, 01 Mar 95 09:08:00 PST
To: FIREWALLS <firewalls @ GreatCircle . COM>

> Brian W. McKenney wrote:
>I am looking for information on commercial off-the-shelf (COTS) encryption
products that can be used to provide firewall-to-firewall encryption
(node-to-node).  The device would encrypt based on source/destination
address and if possible by network service (port).

>One of our customers has a network of firewalls and they would like to
protect their network traffic over the Internet (firewall-to-firewall) but
still be able to communicate with the outside world.  The firewall
configuration is the same at each of the nodes.  At the present time, a
user must go through a challenge/response sequence at each firewall.  The
customer is exploring security technologies that could eliminate the need
for a challenge/response dialogue at each firewall.
 ----
Careful here.  In my conversations with various vendors, it is not certain
that firewall-to-firewall encryption, as currently designed, will work
between different vendors of firewalls.  This probably isn't a concern for
your customer as you imply that all of their firewalls are identical (same
vendor).

William Wells
Manager, Technical Support
Damark International


Follow-Ups:
Indexed By Date Previous: Re: Firewall-to-Firewall Encryption
From: Ted Doty <ted @ kgbvax . network . com>
Next: Node based security (Was: Re: No Out-Of-The-Box Security)
From: horn @ mickey . jsc . nasa . gov
Indexed By Thread Previous: Re: Firewall-to-Firewall Encryption
From: Ted Doty <ted @ kgbvax . network . com>
Next: Re: Firewall-to-Firewall Encryption
From: "Marcus J. Ranum" <mjr @ tis . com>

Google
 
Search Internet Search www.greatcircle.com