Great Circle Associates Firewalls
(November 1995)
 

Indexed By Date: [Previous] [Next] Indexed By Thread: [Previous] [Next]

Subject: Re: WWW server in a screened subnet or in internal net ?
From: Rick Smith <smith @ sctc . com>
Date: Fri, 17 Nov 1995 12:35:20 -0600
To: firewalls @ greatcircle . com
Cc: smith @ sctc . com, jlc @ adnt . fr

I probably won't be the only person to respond to the question by
Jean-Luc CHARDON <jlc @
 adnt .
 fr>:

>A WWW service is to be established on a UNIX server which will provide info to
>remote users. All available data is for general public (no restricted data) 
>and the server can be dedicated to www service.

>I have, at least, two solutions :
>A) establish the service on a sacrificial host in the screened subnet
>B) establish the service on an internal host and use the proxy http-gw
>   to forward clients calls to the server.

Ask yourself what happens if the Web software contains a bug and
allows an attacker to penetrate the system (after all, you're
asking a security mailing list, eh?).

In A) you've lost your sacrificial host and the attacker is still
outside the protective perimeter established with your firewall.

In B) the attacker is inside the protective perimeter established with
your firewall. This is not a good thing.

A third option is to host it on a system with mandatory protections
like Sidewinder or something with military style security labels.  In
a dual homed configuration you could administer from one side, connect
the other to the Internet, and use the mandatory protection to keep
Internet attackers from touching the inside network.

Rick.
smith @
 sctc .
 com         secure computing corporation

Indexed By Date Previous: Re: Microsoft's RAS
From: Michael Nelson <mikenel @ netcom . com>
Next: Re: Thats How Netscape does it!
From: Mike Shaver <shaver @ neon . ingenia . com>
Indexed By Thread Previous: WWW server in a screened subnet or in internal net ?
From: Jean-Luc CHARDON <jlc @ adnt . fr>
Next: Re: WWW server in a screened subnet or in internal net ?
From: frankw @ in . net (Frank Willoughby)

Google
 
Search Internet Search www.greatcircle.com