Great Circle Associates Firewalls
(September 1996)
 

Indexed By Date: [Previous] [Next] Indexed By Thread: [Previous] [Next]

Subject: Re: Request for Information (Security for Educational Research Institute)
From: lists @ lina . inka . de (Bernd Eckenfels)
Date: Fri, 20 Sep 1996 04:02:41 +0200 (MET DST)
To: Firewalls @ GreatCircle . COM
In-reply-to: <Pine . SUN . 3 . 93 . 960919144446 . 11688F-100000 @ admin . ogi . edu> from "Don Weston" at Sep 19, 96 02:54:43 pm

Hi,

> Also, given the oddness of our network conditions, our solution is likely to
> differ from classical textbook cases:  We have two Internet Services
> Providers, one of which maintains an ATM WAN, and a number of internal
> networks, one of which is completely separate and homed to the second ISP.
> In addition to this routing pretzel, we have researchers who create new
> protocols every month.

I would suggest that you divide you networks into different pieces. An
internal Office Net, a Testnet, a DEveloper Net. Secure those Nets with
firewalls or packet filters according to the security needs of the specific
net. Youhave to write down which information is allowed to be stored on
which host. Testhosts for example should never host Production-Sourcecode,
or never put Employee Data on anything outside of the secure internal net.
You simply cant ensure perimeter security if you that much links in a
changing environment.

Greetings
Bernd
-- 
  (OO)      -- Bernd_Eckenfels @
 Wittumstrasse13 .
 76646Bruchsal .
 de --
 ( .. )   ecki @
 {lina .
 inka .
 de,linux.de}  http://home.pages.de/~eckes/
  o--o     *plush*  2048/A2C51749  eckes @
 irc  +4972573817  *plush*
(O____O)       If privacy is outlawed only Outlaws have privacy


References:
Indexed By Date Previous: Draft NT/UNIX Network Security Whitepaper posted
From: Bill Stout <bill . stout @ hidata . com>
Next: Re: CIA Firewalls?
From: Adam Shostack <adam @ homeport . org>
Indexed By Thread Previous: Request for Information (Security for Educational Research Institute)
From: Don Weston <don @ admin . ogi . edu>
Next: CIA Site News
From: David Eisenstein <davide @ acekids . com>

Google
 
Search Internet Search www.greatcircle.com