Great Circle Associates Firewalls
(May 1995)
 

Indexed By Date: [Previous] [Next] Indexed By Thread: [Previous] [Next]

Subject: Re: Firewall-to-Firewall Encryption Products
From: Michael Richardson <mcr @ milkyway . com>
Organization: Milkyway Networks Corporation
Date: Fri, 5 May 1995 18:29:44 -0400
To: mckenney @ smiley . mitre . ORG
Cc: firewalls @ greatcircle . com
In-reply-to: <v01510102abccf245606f @ [128 . 29 . 140 . 130]>
Newsgroups: milkyway.mail.firewalls

In article <v01510102abccf245606f @
 [128 .
 29 .
 140 .
 130]> you write:
>Milkyway Black Hole
>  - Supports modified (proprietary) DES algorithm (DES++).

  This is DES with some trivial obscuring code, we haven't modified
the code code.
  We would like to support GSSAPI on top of a swIPe-like facility, but
since swIPe doesn't define any standard encryption yet, we are waiting
for an available commercial GSSAPI. (e.g. NT Entrust)
  I suspect this will be the solution for interoperability.

>configuration is the same at each of the nodes.  At the present time, a
>user must go through a challenge/response sequence at each firewall.  The
>customer is exploring security technologies that could eliminate the need
>for a challenge/response dialogue at each firewall.

  Essentially all virtual private network software winds up doing a
small amount of packet filtering/routing to get the packets to the
remote network to go through the encryption engine.

  In Black Hole, if you decide *not* to trust the packets coming from
the "encrypted virtual interface", then they don't get routed, and
must pass through the normal Black Hole proxies. e.g. branch office
can login to HQ, but they must authenticate, and their packets get
encrypted so no one can hijack the connection.
  Or, you can just route the packets.





-- 
   :!mcr!:            |     <A HREF="http://www.milkyway.com/";>Milkyway Networks Corporation</A>
   Michael Richardson |   Makers of the Black Hole firewall 
 NCF: aa714 || xx714  | +1 613 566-4574 ... mcr @
 milkyway .
 com
 Home: <A HREF="http://www.sandelman.ocunix.on.ca/People/Michael_Richardson/Bio.html";>mcr @
 sandelman .
 ocunix .
 on .
 ca</A>. PGP key available.


References:
Indexed By Date Previous: Re: PC site security
From: "S. Alexander Jacobson" <alex @ virtual . office . com>
Next: What if I don't have a proxy for my application?
From: Edward Maillet <maillet @ doc . usmcs . maine . edu>
Indexed By Thread Previous: Re: Firewall-to-Firewall Encryption Products
From: vick <vick @ lerc . nasa . gov>
Next: packet filtering software
From: Maurice . Yergeau @ Toro . Com

Google
 
Search Internet Search www.greatcircle.com