On Sat, 25 Nov 1995, Brent Chapman wrote:
> Every reasonable firewall I can think of is capable of meeting the second
> condition above, for the network architectures used by most sites. The
> question each individual site has to ask is, can they meet the first
> condition above (i.e., can they say "we don't trust anything beyond our
> perimeter", and actually get away with it). Many (most?) sites can, some
> can't.
Nameservice usually seems to be a major exception. Everyone trusts
nameservers by IP address to locate other machines. Hopefully only
outside of their perimiter.
Nick Simicich - njs @
scifi .
emi .
net - (last choice) njs @
bcrvm1 .
vnet .
ibm .
com
http://scifi.emi.net/njs.html -- Stop by and Light Up The World!
References:
|
|