[fw-wiz] Firewalling between T-1's, an ATM switch and a switched office

From: Steven Ackerman (ackerman_steven@yahoo.com)
Date: 03/14/03

  • Next message: m p: "Re: [fw-wiz] Firewalling between T-1's, an ATM switch and a switched office"
    From: Steven Ackerman <ackerman_steven@yahoo.com>
    To: firewall-wizards@honor.icsalabs.com
    Date: Fri, 14 Mar 2003 14:57:43 -0800 (PST)
    

    Greetings,

    I work for a small network consulting firm. Security
    has not been researched or applied much prior to my
    arrival. I am trying to change that, although I have
    limited understanding and less experience.

    The person I work for directly is trying to setup a
    Watchguard box with content filtering between two
    switches and 4 t-1 lines. The setup is as follows:

    ATM switch with one incoming internet connection, 4
    t-1's on the inside (each goes to a different school),
    2 Ethernet ports. One ethernet (eth 0) port has a
    cisco switch which connects another office. The second
    (eth1) ethernet port connects a watchgaurd box. The
    Watchgaurd box has 3 ethernet ports on it.

    My boss wants to route incoming traffic through the
    Eth0 port to the switch and then to the watchgaurd box
    and to the appropriate t-1/school and visa verse
    (sp?). It looks to me like this bypasses the firewall.

    Can this work through ACL's at the ATM switch. Is this
    unsafe. How can I explain this is unsafe to an admin
    that doesn't see how it is unsafe when he can use
    ACL's on source and destination IP's and ports?

    Any help would be appreciated. Although I've followed
    this and the other firewalls list's (and all the
    infosec god's I know of) for years, I'm very new to
    all this. This is my first hands on exposure to
    security.

    -Steve

    __________________________________________________
    Do you Yahoo!?
    Yahoo! Web Hosting - establish your business online
    http://webhosting.yahoo.com
    _______________________________________________
    firewall-wizards mailing list
    firewall-wizards@honor.icsalabs.com
    http://honor.icsalabs.com/mailman/listinfo/firewall-wizards


  • Next message: m p: "Re: [fw-wiz] Firewalling between T-1's, an ATM switch and a switched office"

    Relevant Pages

    • Re: Scart switch box
      ... very interested to know how the ethernet ports are used. ... Including the camera, I have 3 non-RGB sources, that go via a manual switch ... from the Quintro goes around the rest of the house via a relay SCART output ... Programmable input channel display enabling customers to customise each ...
      (uk.tech.digital-tv)
    • Re: Are there faster waps than dwl2100AP
      ... I'm not into complex and elaborate. ... When you connect a switch or hub to another switch or hub, ... or you might be lucky and own a switch or router ... Switches and hub ethernet ports, are wired to talk directly to the ...
      (alt.internet.wireless)
    • Re: 2200 M2 LOM blues
      ... both the main box and LOM fall silent. ... The above seems to be the best clue. ... Have you looked beyond the box, are the ethernet ports of the machine and ... the SP/lom connections fed into the same ethernet switch or hub? ...
      (comp.sys.sun.hardware)
    • Re: TCP stack is pooched
      ... Yes you are correct the switch is an SMC broadband ... router, w/ four ethernet ports, running DHCP. ... > To obtain an IP from an external device it need a DHCP server. ...
      (microsoft.public.windowsxp.network_web)