Great Circle Associates Firewalls
(January 1998)
 

Indexed By Date: [Previous] [Next] Indexed By Thread: [Previous] [Next]

Subject: Re: SNI revised -- (was: Fraudulent SA's solved)
From: Stepken <stepken @ www . firmen-info . de>
Organization: Freie Software Systeme
Date: Wed, 21 Jan 1998 08:27:58 +0100
To: Bernd Eckenfels <lists @ lina . inka . de>
Cc: daemond @ ibm . net, Ryan Russell <ryanr @ sybase . com>, firewalls @ GreatCircle . COM
References: <8825658F . 007A513A . 00 @ gwwest . sybase . com> <Pine . NEB . 3 . 96 . 980117202559 . 27493A-100000 @ master . ibmcyrix . org> <19980120052158 . 54032 @ lina>

Bernd Eckenfels wrote:
> 
> Hello,
> 
> > the only hub in your security it could pose a serious problem).  The two hub
> > design is stronlg recommended (and with just the above few thoughts I can
> > see why) in one of the books that I read (I think it was Building Internet
> > Firewalls by Chapman and Zwicky).  L8r.
> 
> There is a drawback in the two hub design.. you cant control IP Spoofing on
> the second (inner router) very good. Since you dont know if the originator
> in the middle interface is from the internet (the outer router) or from any
> host on the DMZ. This means DMZ Hosts are able to Fake any outside IP
> Address. (and, even worse, sniff the answers. Not that i would recommend any
> authentication based on it).

Yes, in the DMZ the www/ftp...servers really should have a switch.
This makes it much safer. In the book there are some more grave bugs.
Im am working on some corrections, which i will post next weeks.

cu, Guido Stepken


References:
Indexed By Date Previous: Re: FW-1 v3.0 on NTv4.0 (with SP3 and FW-1 patches)
From: "Billy Verreynne" <vslabs @ onwe . co . za>
Next: RE: access website through firewall
From: Thomas Liam Romanis <TLR @ portcullis-security . com>
Indexed By Thread Previous: Re: SNI revised -- (was: Fraudulent SA's solved)
From: daemond @ ibm . net
Next: Re: SNI revised -- (was: Fraudulent SA's solved)
From: "Ryan Russell"<ryanr @ sybase . com>

Google
 
Search Internet Search www.greatcircle.com