Great Circle Associates Firewalls
(March 1997)
 

Indexed By Date: [Previous] [Next] Indexed By Thread: [Previous] [Next]

Subject: Re: ACL vulnerability
From: dharris @ kcp . com
Date: Mon, 3 Mar 1997 18:08:31 -0600
To: firewalls-digest <firewalls-digest @ greatcircle . com>, "Benvenuto; Vincent A." <vbenvenu @ faxint . com>

Router ACLs filter based on port, IP address, or MAC address - correct?

MAC address is useless once you pass the first router - right?

IP address can be spoofed "easily"

How tightly controlled is physical access to your partners' machines?  Do you 
trust ALL employees at your partners' sites equally?  How about the vendor they 
have on-site doing unsupervised repair on network-connected systems?

How much do you stand to lose if the "wrong person" gains access to your site?  
Is your internal protection strong enough that you want to let unspecified 
individuals have access to your entire network?



______________________________ Reply Separator _________________________________
Subject: ACL vulnerability
Author:  "Benvenuto; Vincent A." <vbenvenu%faxint .
 com @
 cerberus2 .
 kcp .
 com> at 
INTERNET-MAIL
Date:    3/3/97 1:33 PM



We are in the middle of a great debate as to the proper way to firewall 15 
remote sites.  We need to essentially open dedicated lines to our partners 
to allow incoming/outgoing FTP, X.400, and SMTP. One camp says ACLs in 
routers will be sufficient, another says stick with Firewall-1 and 
proliferate it like hell.  The cost difference network wide between the two 
approaches is huge.

Where can I find an (authoritative) threat analysis that describes the 
vulnerability of router based static ACLs (non-stateful inspection)?  Also, 
what methods (toolsets) are available to launch attacks through a router 
configured with ACLs?  any advice suggestions, etc appreciated.

Thanks in advance.

Vinnie B

Indexed By Date Previous: sniffer!
From: Jose Luis Delgado <jdelgado @ nexus . net . mx>
Next: Re: Firewall OS
From: Bernd Eckenfels <lists @ lina . inka . de>
Indexed By Thread Previous: ACL vulnerability
From: "Benvenuto, Vincent A." <vbenvenu @ faxint . com>
Next: NAT
From: "Jim Leo" <ADMIN @ everett . pitt . cc . nc . us>

Google
 
Search Internet Search www.greatcircle.com