Great Circle Associates Firewalls
(December 1995)
 

Indexed By Date: [Previous] [Next] Indexed By Thread: [Previous] [Next]

Subject: Re: Firewall-1, any hints or gotcha's in it's installation??gy
From: David Kovar <kovar @ NDA . COM>
Date: Wed, 20 Dec 1995 17:23:38 -0500 (EST)
To: craiga @ Ipsilon . COM (Craig Anderson)
Cc: adam @ bwh . harvard . edu, philips @ textwise . com, Firewalls @ GreatCircle . COM
In-reply-to: <199512201952 . LAA11152 @ mailhost . Ipsilon . COM> from "Craig Anderson" at Dec 20, 95 11:52:15 am

> > 	Don't forget to harden the underlying OS before installing, a
> > point which the manual makes no mention of.  I've seen FW-1s running
> > on a Sun with Sun's shipped sendmail.  Hmmm.  If you're already
> > running FWTK, you've probably done this, but there are a number of
> > vendors who say 'our OS is good enough for a firewall.'
> > 
> > Adam
> > 
> I say that this is not necessary.  If you set up your filters
> correctly, then Solaris will never see any packets it's not
> supposed to since the filters operate between the ethernet
> driver and the higher protocol stacks.  The key is to set up
> the filters correctly; i.e. don't allow any communication to
> the firewall itself.
> 
> Craig

  While this is true, it is good practice to disable those services
that you do not need and to secure those services you do need
as a matter of course. I've a lot of faith in FW-1, but I have more
faith in just shutting the services down if I don't need them.

  And if you shut down the services *and* configure your filters correctly,
you can sleep even more soundly at night.

-David




References:
Indexed By Date Previous: re: Dial-ups
From: Tony Iannotti <tony @ secapl . com>
Next: Re: caching protected documents (fwd)
From: Brain21 <brain21 @ montag33 . residence . gatech . edu>
Indexed By Thread Previous: Re: Firewall-1, any hints or gotcha's in it's installation??
From: Craig Anderson <craiga @ Ipsilon . COM>
Next: Re: Firewall-1, any hints or gotcha's in it's installation??
From: Brain21 <brain21 @ montag33 . residence . gatech . edu>

Google
 
Search Internet Search www.greatcircle.com