Great Circle Associates Firewalls
(March 1995)
 

Indexed By Date: [Previous] [Next] Indexed By Thread: [Previous] [Next]

Subject: Firewalling DecNet
From: padgett @ tccslr . dnet . mmc . com (A. Padgett Peterson, P.E. Information Security)
Date: Thu, 30 Mar 95 10:13:54 -0500
To: "firewalls @ greatcircle . com"@UVS1.dnet.mmc.com

>We have a situation in which we need to separate a some machines that need to
>communicate via DecNet protocols (they all run VMS).  One set of machines is
>less trusted than the other and we would like to have some method of
>partitioning the machines with a firewall of some sort.

Well basically DecNet is just another Ethernet "type" like IP so the
obvious answer is to create two subnets, one with the trusted ones, the
other with those less trusted and filter crossings based on MAC addresses
(AFAIR that is what DECnet uses). I believe that there are any number
of devices that can handle subnet filtering/isolation. Now if you want
to allow some communications you have a different problem. The same
structure applies but it depends of what, and with which, and to whom your
policy allows.

Short answer: you can but <insufficient data>.
						Warmly,
							Padgett


Indexed By Date Previous: ADDENDUM: Brief report on Firewalls BoF from Networld+Interop, Las Vegas
From: Frederick M Avolio <avolio @ tis . com>
Next: Re: Screend & ftp
From: Frank Wortner <frank @ prodigy . com>
Indexed By Thread Previous: Re: ADDENDUM: Brief report on Firewalls BoF from Networld+Interop, Las Vegas
From: Darren Reed <avalon @ coombs . anu . edu . au>
Next: Re: Firewalling DecNet
From: "Thomas Clark - (319)395-5045" <TGCLARK @ hobbes . cca . rockwell . com>

Google
 
Search Internet Search www.greatcircle.com