Disclaimer:
I'M NOT A NETWARE/IPX FIREWALL EXPERT....
THESE ARE NOT THE OFFICIAL OPINIONS OF NOVELL....
I'M NOT GOING TO DISCUSS CURRENT PRODUCT DEVELOPMENT EFFORTS
INSIDE NOVELL THAT MAY IMPACT THE FUTURE SPIN OF THIS SUBJECT...
That said, unless you're doing IPX over IP tunnelling, the fact that
you have a primarily NetWare environment does not really change things,
as PC's and NetWare servers with IP packages do the same basic things as Unix
systems with IP (ftp, smtp, NFS, etc).
So...you should be able to build the same sort of IP firewall you'd build
for a Unix shop.
If this is actually an IPX firewall, (we've got some of those around
here, though I haven't designed/built any of them), things are a
bit different, but I won't get into that (and don't think I'm
qualified to).
If you intend to have PC's _without_ an IP stack access an IP
firewall, there are several additional options on the market for
proxying through a NetWare server, but, again, I don't think I'm
qualified to offer advise on these.
Don't know anything about the InterNetware product mentioned, either.
--
Christopher J. Calabrese
Network Security Architect
Novell Information Services & Technology, Summit, NJ
cjc @
summit .
novell .
com
> To: firewalls @
greatcircle .
com
> From: david @
goodman .
com (David S. Goodman)
> Subject: Firewalls and Novell
> Sender: firewalls-owner @
GreatCircle .
COM
> Precedence: bulk
> Status: R
>
> I'm trying to get some information on firewalls in a Netware environment.
> Most (if not all) of the things that I've read on the net (FAQs, white
> papers, etc.) do not discuss PCs or Novell. Can anyone shed any light on
> this? For instance, if I'm using a TCP/IP stack such as SuperTCP or
> LANWorkplace for DOS, what kinds of risks am I facing? Are they any
> different than the risks that Unix environments face? Are there any
> resources that have information on this kind of thing (I've tried Novell to
> no avail)? Any thoughts would be greatly appreciated.
>
> Also, there's a product called IWare from a company called InterNetware.
> They say that it's a firewall for Netware networks built around Netware's
> existing TCP/IP NLMs. Does anyone have any experience with this company or
> product?
>
> Please reply to david @
goodman .
com .
TIA.
> ====================================
> David S. Goodman
> david @
goodman .
com
> Voice: 212-595-7473
> Fax: 212-595-8951
|
|