Great Circle Associates Firewalls
(September 1996)
 

Indexed By Date: [Previous] [Next] Indexed By Thread: [Previous] [Next]

Subject: Re: Newbie question
From: "Mr. Jolt Cola" <msmith @ quix . robins . af . mil>
Date: Tue, 17 Sep 1996 20:03:09 -0400 (EDT)
To: smith @ sctc . com (Rick Smith)
Cc: firewalls @ greatcircle . com
In-reply-to: <v01540b0dae64ce4bb479 @ [172 . 17 . 1 . 61]> from "Rick Smith" at Sep 17, 96 04:01:46 pm

> At 3:25 PM 9/17/96, Chris Garrigues wrote about Mark's picture
> of a "triple homed" firewall:
> 
> >I see maps like yours all the time, but I'm uneasy about real
> >routing happening on my firewall.  It just seems to me like
> >there's potential risk in running routing software on a firewall.
> 
> Quite so. Correct packet flow must be enforced by something more than IP
> level routing. The picture only makes sense if you've set up a firewall
> proxy to enforce the flow. All web server accesses should be sent to the
> isolated subnet containing the Web server and no incoming Internet
> connections should be allowed to flow directly into the database server's
> net. The "routing" in this case isn't handled by the IP layer, it's handled
> by socket layer proxies.
> 
> Rick.

Ok, you guys are great, I appreciate everyone that responded.
Hopefully I have enough with which to make a sound decision, and
I'll continue to lurk in either case. :)

	Melvin


References:
Indexed By Date Previous: IPX filtering
From: Nassim Chaabouni <chaabouni @ houston . omnes . net>
Next: NT vs. UNIX white paper
From: Bill Stout <bill . stout @ hidata . com>
Indexed By Thread Previous: Re: Newbie question
From: smith @ sctc . com (Rick Smith)
Next: Re: Newbie question
From: "Mr. Jolt Cola" <msmith @ quix . robins . af . mil>

Google
 
Search Internet Search www.greatcircle.com