Great Circle Associates Firewalls
(June 1997)
 

Indexed By Date: [Previous] [Next] Indexed By Thread: [Previous] [Next]

Subject: Re: Remote management of firewalls internationally
From: Alan <alano @ teleport . com>
Date: Mon, 30 Jun 1997 16:31:16 -0700 (PDT)
To: Mark Teicher <mht @ clark . net>
Cc: firewalls @ GreatCircle . COM
In-reply-to: <3 . 0 . 1 . 32 . 19970630102958 . 008fe7f0 @ clark . net>

On Mon, 30 Jun 1997, Mark Teicher wrote:

> A suggestion from a close and wise friend asked me to inquire about this:
> 
> 
> How can one remotely manage firewalls that are on the other side of the world?
> How can it be done? and done safely?

Maybe.

As well as if you had physical access to the machine?  No.

If you have SSH or some other form of encryption/authentication between
machines, then you should be able to maintain the firewall without too
many problems.  (Some sort of token-based authorization system or Public
Key system would be a big plus and/or requirement in such a system.)

I would be concerned with elements like the physical security of the
machine.  Can you trust the location and the personnel of the site not to
comprimise the security of the firewall?  If you have hardcopy of the
server logs for verification, how is that handled?

The logistics of maintaining the site would be a pain, but not totally
impossible.

I guess it depends alot on the firewall software you are using...

alano @
 teleport .
 com | "Those who are without history are doomed to retype it."



Follow-Ups:
References:
Indexed By Date Previous: Security Expert (TM)
From: Jack Danahy <jdanahy @ bbn . com>
Next: ICQ network
From: Joe Pollock <pollockj @ elwha . evergreen . edu>
Indexed By Thread Previous: Remote management of firewalls internationally
From: Mark Teicher <mht @ clark . net>
Next: Re: Remote management of firewalls internationally
From: Ken Hardy <ken @ bridge . com>

Google
 
Search Internet Search www.greatcircle.com