Great Circle Associates Firewalls
(April 1996)
 

Indexed By Date: [Previous] [Next] Indexed By Thread: [Previous] [Next]

Subject: Re: Packet Filtering - I'm Stuck
From: bobk @ manzanita . DEV . 3Com . COM (Bob Konigsberg)
Date: Fri, 12 Apr 96 13:38:02 PDT
To: firewalls @ greatcircle . com, ac141 @ typhoon . dial . pipex . net

Given a frame relay link (or any other kind) to an outside company, 
you should first have a firewall between you and them.

For simplicity (You can always get more elaborate) this can be a packet
filtering router.  In this case, you set filters that allow the precise
type of traffic (Telnet, FTP, SMTP, whatever) that they are allowed to
do, and the hosts that they are allowed to contact in whatever manner.

On top of that, I'm going to assume that you use propagation of the default
route (0.0.0.0) to lead all packets to your ISP.

There are two steps that should be in place which will both protect you,
but you should have them anyway.

1) The only IP addresses that are advertised out to the Internet should
be yours, and not this other outfit.  This is controlled either by BGP4,
or static routing between you and your ISP.

2) You should have on the firewall (router, or router in front of another
firewall) route advertising policies which limit what route advertising
the other outfit is allowed to see.  The default route should NOT be on 
this list.

Without more specific information, I can't guess at your config.  If the
other outfit is using a peice of your class C or class B (or whatever),
then you will need to add filters to make sure that they can only get
to whatever they are supposed to and nothing else.

BobK

Indexed By Date Previous: Re: internet connection
From: Mike Eddington <damdum @ nowhere_linux . nowhere . aetna . com>
Next: Re: Solaris2.5 and BSD* - Facts
From: peter @ nmti . com (Peter da Silva)
Indexed By Thread Previous: RE: Packet Filtering - I'm Stuck
From: Gavin Ferreiro <gavin @ tml . co . za>
Next: RE: Packet Filtering - I'm Stuck
From: Adam Safier <asafier @ explorer . csc . com>

Google
 
Search Internet Search www.greatcircle.com