Firewall & Dual NIC Interfaces.

From: Robert Bastell <trodat_at_jasper.rdc.ab.ca>
Date: Wed, 21 Jul 1999 11:53:33 -0600 (MDT)

Last time I came here for support I got GREAT help, thanks!

I'm running a 1000a with 4.0E with two NIC cards. One of
the interfaces is connected and statically routed (including
default gateway) in the DMZ of our firewall zones.

The second is routed to our internal network with static
routes to our subnet ranges.

I have disabled all routing, other services that I could see
might enable a user to tunnel through. I have to leave
running due to the nature of the box:

http (inside/outside)
ftp (inside)
smtp (inside/outside)
nntp (inside/outside)
imsp (inside)
smsauthd (inside)

The machine outside of the network cannot be port scanned due to
the nature of the firewall, inside it can but to only the internal
network NIC.

The department manager wants proof that this system does not violate
security and integrity of the firewall.

I can procur more information if required, but can someone give me
good advice or a URL to view either supporting myself or confirming the
manager's suspicions.

Appreciation well in advance of your help.

Robert Bastell
Webmaster - Information And Learning Resources
Red Deer College

The above does not necessarily reflect the views
or opinions of Red Deer College.
Received on Wed Jul 21 1999 - 18:01:33 NZST

This archive was generated by hypermail 2.4.0 : Wed Nov 08 2023 - 11:53:39 NZDT