Great Circle Associates Firewalls
(August 1995)
 

Indexed By Date: [Previous] [Next] Indexed By Thread: [Previous] [Next]

Subject: RE: appletalk and ipx dangers?
From: lbe @ login . dknet . dk (Lars Bertelsen)
Date: Thu, 3 Aug 1995 07:34:42 +0200
To: firewalls @ greatcircle . com

marc @
 bbb .
 com .
 au writes:
>>Watch out for IPGATEWAYs. If you run MacIP encapsulation or IPX encapsulation
>>on that access server, you will effectively be bypassing any firewalling of
>>IP.
>>Unscreened IP packets can then pass into your corporate net using the other
>>protocols as transport.
>>
>>Cheers,
>>Marc Bailey
>>__________________________________________________________________________
>>_____
>From: Mark Saltzman on Thu, 3 Aug, 1995 9:03 AM
>Subject: appletalk and ipx dangers?
>To: firewalls @
 GreatCircle .
 COM
>
>Does anyone see any danger in allowing ipx and appletalk traffic to be
>routed through my firewall?
(cut!)

Well, that is both true and untrue, isn't it? I suppose if the IP gateway
that users connect to at dial-in time runs ON the firewall machine, then
users who use this service might be able to use this mechanism to bypass
the firewall.
Users from the Internet wouldn't be able to, though, since the router to
the internet wouldn't have to route IPX/Apletalk.
One thing to be aware of is that if there is an IP-gateway running inside
the firewall in any Appletalk zone then a user would be able to change his
setup at home to get his IP address from that one instead of the one
running in the unsafe zone. That of course would give him unlimited access
to the internal network and be entirely unsafe!


lbe @
 login .
 dkuug .
 dk
Lars Bertelsen
Gartnervang 29 Roskilde, DK



Indexed By Date Previous: Re: IPWatcher
From: Mark <mark @ lochard . com . au>
Next: TIS on solaris 2.4?
From: F . Wetzels @ amc . uva . nl
Indexed By Thread Previous: RE: appletalk and ipx dangers?
From: "marc" <marc @ bbb . com . au>
Next: Subnet Mask for Firewall Setup
From: Ruiyuan_Jiang/Advantage_KBS_at_LotusXchg @ njcorp . akbs . com

Google
 
Search Internet Search www.greatcircle.com