Great Circle Associates Firewalls
(February 1998)
 

Indexed By Date: [Previous] [Next] Indexed By Thread: [Previous] [Next]

Subject: Re: screened subnet firewall
From: Henry Hollenberg <speed @ barney . iamerica . net>
Date: Sat, 21 Feb 1998 07:27:36 -0600 (CST)
To: Firewalls @ GreatCircle . COM
In-reply-to: <199802210334 . TAA12939 @ honor . greatcircle . com>

Mario Biron <mario @
 almerco .
 ca> wrote:

"I tried both method and decided to go with masquerading...."

Yeah, that's probably the best way, I guess I was trying to
avoid setting up the masquerade.....I guess it's just one
more thing to figure out!

I guess it goes on the internal router....right?

-inet

-outer router (pipeline 50 running secure access software for flexible IP
filters)

-perimeter net with bastion host as above (I guess I'll need to subnet my
class C in 
 half to make the IP filter rules work for the three networks.

- inner router (another stripped down bastion host Debian linux machine)
  ^^^^^^^^^^^^
  ||||||||||||
- inner network - my hosts and internal mail hub/DNS.

	Henry Hollenberg     speed @
 barney .
 iamerica .
 net 



Indexed By Date Previous: Re: CISSP Certification -rebuttle
From: mht @ clark . net
Next: Re: Harsh Security audits?
From: Rabid Wombat <wombat @ mcfeely . bsfs . org>
Indexed By Thread Previous: Re: screened subnet firewall
From: Mario Biron <mario @ almerco . ca>
Next: Re: screened subnet firewall
From: Mario Biron <mario @ almerco . ca>

Google
 
Search Internet Search www.greatcircle.com