Great Circle Associates Firewalls
(April 1997)
 

Indexed By Date: [Previous] [Next] Indexed By Thread: [Previous] [Next]

Subject: Telnet (through Firewall)
From: PAUL . SMITH @ arpstl-emh2 . army . mil
Date: Thu, 24 Apr 1997 07:51:18 -0400
To: " - (052)Firewalls(a)GreatCircle.COM" <Firewalls @ GreatCircle . COM>
X400-content-type: P2-1988 (22)
X400-mts-identifier: [/ADMD=BLANK/C=US/;0008200001247052000002]
X400-originator: PAUL . SMITH @ arpstl-emh2 . army . mil
X400-recipients: Firewalls @ GreatCircle . COM

     Pardon me as I am sure this question has been approached before..


     My Co. is using IBM's SNG (running on a RS/6000 w/ AIX) as our
     firewall.  From the strategies I have observed listening to this list,
     I have moved much of the overhead away from the Firewall.  Our
     firewall used to serve as a SOCKS Proxy, and now I have moved that
     overhead to a Netscape Proxy Server.  Now the firewall serves as just
     a divider between the public and private.  This strategy seems a lot
     cleaner to me, thanks list.

     And now my question:

     I have recently been hit with requests for Telnet access from public
     hosts to the private side of our network (through the firewall).  What
     is the current strategy in regards to this?

     One possibility I see is to break the process at the firewall and
     setup Telnet enabled accounts there.  Have the user Telnet into the
     firewall, and then from the firewall to our internal hosts.  This
     method seems "unclean" to me...Not to mention the overhead on the side
     of the users to have to FTP their data to the firewall and then from
     the firewall to the internal host...??  Thanks in advance for any
     suggestions...


     Paul


Follow-Ups:
Indexed By Date Previous: Proxy vs. Stateful Inspection
From: "Dan DeWaal" <dewaald @ sprynet . com>
Next: Re: Secure Email Client Packages...
From: Robin J Smith <robin @ Internet-SmartWare . com>
Indexed By Thread Previous: Re: Proxy vs. Stateful Inspection
From: Darren Reed <avalon @ coombs . anu . edu . au>
Next: Re: Telnet (through Firewall)
From: Frederick M Avolio <avolio @ tis . com>

Google
 
Search Internet Search www.greatcircle.com