Great Circle Associates Firewalls
(January 1998)
 

Indexed By Date: [Previous] [Next] Indexed By Thread: [Previous] [Next]

Subject: Re: SNI revised -- (was: Fraudulent SA's solved)
From: Bernd Eckenfels <lists @ lina . inka . de>
Date: Tue, 20 Jan 1998 05:21:58 +0100
To: daemond @ ibm . net
Cc: Ryan Russell <ryanr @ sybase . com>, firewalls @ GreatCircle . COM
In-reply-to: <Pine . NEB . 3 . 96 . 980117202559 . 27493A-100000 @ master . ibmcyrix . org>; from daemond @ ibm . net on Sat, Jan 17, 1998 at 08:30:45PM -0500
References: <8825658F . 007A513A . 00 @ gwwest . sybase . com> <Pine . NEB . 3 . 96 . 980117202559 . 27493A-100000 @ master . ibmcyrix . org>

Hello,

> the only hub in your security it could pose a serious problem).  The two hub
> design is stronlg recommended (and with just the above few thoughts I can
> see why) in one of the books that I read (I think it was Building Internet
> Firewalls by Chapman and Zwicky).  L8r.

There is a drawback in the two hub design.. you cant control IP Spoofing on
the second (inner router) very good. Since you dont know if the originator
in the middle interface is from the internet (the outer router) or from any
host on the DMZ. This means DMZ Hosts are able to Fake any outside IP
Address. (and, even worse, sniff the answers. Not that i would recommend any
authentication based on it).

Greetings
Bernd
-- 
  (OO)      -- Bernd_Eckenfels @
 Wendelinusstrasse39 .
 76646Bruchsal .
 de --
 ( .. )  ecki @
 {inka .
 de,linux.de,debian.org} http://home.pages.de/~eckes/
  o--o     *plush*  2048/93600EFD  eckes @
 irc  +497257930613  BE5-RIPE
(O____O)       If privacy is outlawed only Outlaws have privacy


Follow-Ups:
References:
Indexed By Date Previous: Re: Oracle SQL*Net ports from Win3.1
From: "Billy Verreynne" <vslabs @ onwe . co . za>
Next: Re: Firewalls-Digest V7 #30
From: "root" <root @ si . cycare . com>
Indexed By Thread Previous: Re: SNI revised -- (was: Fraudulent SA's solved)
From: daemond @ ibm . net
Next: Re: SNI revised -- (was: Fraudulent SA's solved)
From: daemond @ ibm . net

Google
 
Search Internet Search www.greatcircle.com