Great Circle Associates Firewalls
(May 1996)
 

Indexed By Date: [Previous] [Next] Indexed By Thread: [Previous] [Next]

Subject: Firewall location
From: Bill Stout <bill . stout @ hds-gw . hidata . com>
Date: Tue, 7 May 1996 13:13:58 -0700
To: Firewalls @ GreatCircle . COM

Question:

If placing a firewall at the internet only addresses 20% of the security 
breaches, why not address part of the 80% internal breaches by moving
(the) firewall towards the servers?

Has anyone done this?
                                        |
      Internet---Router---Desktops---Firewall----Servers/Multiuser systems
                                        |

I realize the desktop systems can't have 'services', but hopefully all critical
data will reside on servers only.

BTW - This is for Corporate use, not NSA, not CIA, not Military.  Unless 
        we use Ranum's V-One smartgate software which encrypts all traffic
        between desktops and the firewall anyway.

Bill

<=======10========20====Ruler for Eudora users==50========60========70========80
William B. Stout	| "Stop socialism in America"
Senior Systems Admin 	| 
Hitachi Data Systems	| "Will you just stand idle as the constitution gets 
Open Systems Center	|  hacked for the 'New World Order'?"
Santa Clara, California	| 
408-970-4822		| #include <std_disclaimer.h>
<=======10========20========30========40========50========60========70========80



Follow-Ups:
Indexed By Date Previous: Re: Fakemail (contacting sysadmins)
From: marchany @ vtserf . cc . vt . edu
Next: Re: Java problemites
From: Ian Hoyle <ianh @ itmel . bhp . com . au>
Indexed By Thread Previous: [no subject]
From: Benjamin Allan Smith <archimedes!bens @ uunet . uu . net>
Next: Re: Firewall location
From: "Paul M. Cardon" <pmarc @ fnbc . com>

Google
 
Search Internet Search www.greatcircle.com