Great Circle Associates Firewalls
(May 1997)
 

Indexed By Date: [Previous] [Next] Indexed By Thread: [Previous] [Next]

Subject: Re: How to control own staff's outbound access through firewall proxy?
From: "Rick Low" <rlow @ ewa-canada . com>
Date: Thu, 22 May 1997 09:23:29 -0400
To: fwadmin @ bitmap . com
Cc: firewalls @ greatcircle . com
In-reply-to: <3383244B . D93 @ bitmap . com>

At 17:35 21-05-97 +0100, you wrote:
>I'd be very interested to hear how other people have
>solved the problem of controlling their users' access
>through their Firewall - either with commonly available
>tools or inexpensive commercial solutions.

I have a customer with a Black Hole that apparently has the features you
ask about.  Here's what I've read in the manual; I haven't used these
particular features and I'm going from memory (the manual is across town)
so the actual details may be off a bit.

The Black Hole firewall (www.milkyway.com) offers the capability to
restrict services to specific users or groups of users.  Then it allows the
admin to create userids and passwords that apparently are separate from the
firewall host's accounts.  When a firewall rule is set up to "challenge", a
userid & password prompt is sent when a connection is attempted.

To avoid the problem of re-authenticating every connection, the Black Hole
offers what they call "transparent" mode.  If enabled, additional
connections that occur within the timeout period from the same IP address
do not get challenged.  This allows, e.g., a web browser to be challenged
only once at the beginning of a web-surfing session.


Rick Low
EWA-Canada Ltd.
Ottawa, Canada
+1 (613) 230-6067
rlow @
 ewa-canada .
 com


References:
Indexed By Date Previous: Re: NT Security
From: "Olmy's Jart" <jart @ alcove . wittsend . com>
Next: ftp proxy client
From: rodney . lindner @ saladin . com
Indexed By Thread Previous: Re: How to control own staff's outbound access through firewall proxy?
From: Martin Khoo <martin @ nii . ncb . gov . sg>
Next: RE: How to control own staff's outbound access through firewall proxy?
From: chris michael <cm @ rmsbus . com>

Google
 
Search Internet Search www.greatcircle.com