Great Circle Associates Firewalls
(June 1997)
 

Indexed By Date: [Previous] [Next] Indexed By Thread: [Previous] [Next]

Subject: Re: Restrict Springboarding
From: Ryan Russell/SYBASE <Ryan . Russell @ sybase . com>
Date: 8 Jun 97 9:28:13 EDT
To: Hidayatullah Khan <khanhi @ emirates . com>
Cc: "Firewalls @ GreatCircle . COM" <Firewalls @ GreatCircle . COM>

Your two choices are to put the hosts they do get
access to into a DMZ, or to increase security on all
the other hosts in your network.  In your net, option
2 probably isn't practical.

   Ryan

---------- Previous Message ----------
To: Firewalls
cc: 
From: khanhi @ emirates.com (Hidayatullah Khan) @ smtp
Date: 06/08/97 11:30:23 AM
Subject: Restrict Springboarding

Hello All,
  Ours is a large organization with a class B addressing. We have a
firewall in place to allow outgoing web and mail services.  Often we
have vendors coming in to our systems to support thier applications. Our
firewall is configured to allow the vendors to telnet to specific hosts.
On a couple of occasions I have noticed a vendor's presence on a
different host for which he was not intended to. My question is how can
we restrict a vendor from "springboarding" (i.e telnetting  to other
machines on our network) from the actual specific host.  
Thanks in Adv,
Khan

Khan @
 Bigfoot .
 com






Follow-Ups:
Indexed By Date Previous: Re: ascend routers...
From: valentin @ bios . iuf . net
Next: RE: Restrict Springboarding
From: "Adams, Gavin" <gadams @ ccscns . com>
Indexed By Thread Previous: Re: Restrict Springboarding
From: Bertrum Carroll <bc17684 @ 90 . deere . com>
Next: Re: Restrict Springboarding
From: Adam Shostack <adam @ homeport . org>

Google
 
Search Internet Search www.greatcircle.com