Great Circle Associates Firewalls
(March 1995)
 

Indexed By Date: [Previous] [Next] Indexed By Thread: [Previous] [Next]

Subject: Re: MBONE security
From: ems @ ccrl . nj . nec . com (Ed Strong)
Date: Thu, 21 Jul 94 09:42:35 EDT
To: firewalls @ GreatCircle . COM

A summary of responses of sorts. You probably won't like it.
Basically MBONE falls into the "killer app" category, similar to mosaic.
It's not secure, no one has a fix for it yet.  You accept the important
binaries on faith in order to run it. However MBONE (again like mosaic)
is in such demand that many sites run it nevertheless. (Those "real-time"
space shuttle camera views are too cool to miss.)

I was fortunate to be able to commune in person with various firewall
"gods" last week, at a local security seminar. No one has a good answer yet.

To be consistent about security MBONE should only be available in a DMZ
zone or some such. Glamor aside, unless MBONE is critical to your org's
mission, it should not be let inside at the present time.  The rationale
I keep hearing is that important seminars are held via MBONE. My impression
though, is that at present most of the traffic is the aforementioned cool
video scenes.

and I'm sure everyone has the FW I-net security book so I won't throw that into
this already large message.. In short, there are security risks.

Jeromie Jackson
Garrison Associates
Phone: 619-793-8223
Fax  : 619-793-1124 

Indexed By Date Previous:
From: (nil)
Next: Announcing cisco omega test of 10.3
From: Tony Li <tli @ cisco . com>
Indexed By Thread Previous:
From: (nil)
Next: Announcing cisco omega test of 10.3
From: Tony Li <tli @ cisco . com>

Google
 
Search Internet Search www.greatcircle.com