Great Circle Associates Firewalls
(May 1997)
 

Indexed By Date: [Previous] [Next] Indexed By Thread: [Previous] [Next]

Subject: Re: [FW1] [FW-1] [Solaris 2.6] DHCP, VLSM thoughts
From: Adam Safier <asafier @ csc . com>
Date: Tue, 13 May 1997 22:15:15
To: Eric Deschamps <Eric . Deschamps @ France . Sun . COM>
Cc: Marc Mosko <marc @ tear . com>, "Marc D. Jackson" <dechon @ CS . Stanford . EDU>, Eric . Deschamps @ France . Sun . COM, Jerald . Josephs @ Ebay . Sun . COM, firewalls @ GreatCircle . COM, fw-1-mailinglist @ us . checkpoint . com, drexx @ pspi . com . ph
In-reply-to: <Roam . SIMC . 2 . 0 . 6 . 862913575 . 29341 . edescham @ sunaix>
References: <"Your message with ID" <336E7325 . B14CADEA @ tear . com>

At 12:12 PM 5/6/97 +0200, Eric Deschamps wrote:
>I am not sure that a firewall should deal with routing at all (and with other
>stuff as well). I like the idea of building a perimeter defense with a
>firewall doing only filtering (with states engines) and having some proxies
>for specific applications.
>

A firewall is effectively a router.  The vulnerability that makes people
antsy is the protocols used to update the routing tables.  Most rout update
protocols are subject to being fed misinformation resulting in incorrect
routs, potentially making IP spoofing attacks easier.   The solution of
most firewallers is static routs.

OSPF has a password option to help avoid getting routing areas mixed up -
but it's sent with the updates in the clear.

If you encrypt the link between 2 firewalls you can safely send routing
info.  Just watch the overhead from updates that are too frequent.

Adam

My opinion only counts with those who want it.



Follow-Ups:
References:
Indexed By Date Previous: Re: IRC proxy...which works
From: Bernd Eckenfels <lists @ lina . inka . de>
Next: Re: IRC proxy...which works
From: Nick Simicich <njs @ scifi . squawk . com>
Indexed By Thread Previous: Re: [FW1] [FW-1] [Solaris 2.6] DHCP, VLSM thoughts
From: Eric Deschamps <Eric . Deschamps @ France . Sun . COM>
Next: Re: [FW1] [FW-1] [Solaris 2.6] DHCP, VLSM thoughts
From: Eric Deschamps <Eric . Deschamps @ France . Sun . COM>

Google
 
Search Internet Search www.greatcircle.com