Great Circle Associates Firewalls
(June 1997)
 

Indexed By Date: [Previous] [Next] Indexed By Thread: [Previous] [Next]

Subject: Re: ipfwadm question
From: "Ge' Weijers" <ge @ calamari . Progressive-Systems . Com>
Organization: Progressive Systems, Inc.
Date: Tue, 3 Jun 1997 10:22:08 -0400 (EDT)
To: Firewalls @ GreatCircle . COM
In-reply-to: <199706030631 . XAA11683 @ honor . greatcircle . com> from "Firewalls-Digest" at Jun 2, 97 11:31:23 pm
Reply-to: ge @ progressive-systems . com (Ge' Weijers)

> 		Gateway Box
> 		    |
> 		    |
> 		Firewall Box
> 		    |
> 		    |
> 		LAN Router
> 		  / | \
> 		 /  |  \
> 		/   |   \
> 	  Node 1 Node 2  Node 3
> 

This picture is correct, a 'firewall' is sitting between the Big Bad Internet and
your LAN. The 'LAN Router' would be missing at small sites.

This design has its drawbacks if any of 'Node 1..3' has to be accessible from the
Internet. Say if Node 1 receives e-mail it can be vulnerable to breakins. Anyone
breaking into this machine can then use it as a stepping stone to attack the rest
of your network. You may want to place some hosts on the Internet side of the 
firewall to prevent that from happening. If your Internet gateway has a static
packet filtering capability you can further limit your vulnerability by 
implementing a screened subnet.


          .------------.       .------------.
Internet  |            |       |            |
----------| Gateway    |--+----|  Firewall  |-----+----------+-- . . . .----+
	  |            |  |    |  (Linux)   |     |          |              |
          '------------'  |    '------------'     |          |              |
                          |                       |          |              |
                      .-------.             .---------.  .--------. .---------.
                      |       |             |         |  |        | |         |
                      | Mail  |             | File    |  | User   | |  User   |
                      | Host  |             | Server  |  | PC     | |  PC     |
                      |       |             |         |  |        | |         |
                      '-------'             '---------'  '--------' '---------'

I left out your router as it's irrelevant to the discussion. If you put a couple
of network cards in the firewall host it can double as a router too. I'm doing
just that at the moment, we're running a gateway system with a dynamic packet
filter (a MorningStar SecureConnect) and a Linux box acts as a router and static
packet filter. We also run the TIS firewall toolkit on the Linux box to allow
limited inbound access, though I prefer SSH for that purpose.

Ge'


Indexed By Date Previous: Re: Plug-gw- One to many relationship
From: "Marcus J. Ranum" <mjr @ nfr . net>
Next: Plug-gw- One to many relationship more specific info
From: Ken Kempster <kempster @ monarch . rnb . com>
Indexed By Thread Previous: Re: Bungled password management at WorldNet
From: Steve Bellovin <smb @ research . att . com>
Next: Plug-gw- One to many relationship more specific info
From: Ken Kempster <kempster @ monarch . rnb . com>

Google
 
Search Internet Search www.greatcircle.com