RE: [fw-wiz] Sources for Extranet Designs?

From: Wes Noonan (mailinglists_at_wjnconsulting.com)
Date: 02/23/04

  • Next message: Bob Alberti: "RE: [fw-wiz] Sources for Extranet Designs?"
    To: "'Baumann, Sean C.'" <Sean.Baumann@celera.com>, "'R. DuFresne'" <dufresne@sysinfo.com>
    Date: Mon, 23 Feb 2004 13:31:12 -0600
    
    

    > 1.) If you say you should never allow access to resources on your
    > protected or internal network, how do you handle giving access to
    > services that reside on machines that cannot be duplicated (i.e.
    > expensive mainframes)?

    There are a couple of approaches that I can think of off hand. Approach 1 is
    to design the services with extranet connections in mind. Simply put, maybe
    the mainframe isn't the right place to house that resource. This is probably
    not the answer that you want to hear though. Approach 2 is to accept that
    you have a business limitation that is going to force you to implement a
    less than ideal security solution. At that point, you mitigate it. What
    precise ports need to be opened from the extranet to the internal resource
    and grant *only* that access. If they need SQL access but not NFS access
    then make sure that your firewall only permits SQL traffic to pass between
    the two networks. Things like that.

    > 2.) Do most companies require routable address on their extranet?
    > Currently we use RFC1918 address for our extranet, but we see that this
    > will become a problem in the future as we add partners.

    Depends. Assuming that you are going to be using firewalls and advertising
    your internal resources as something else (through the use of NAT, etc.)
    then you can do that and make the routable addresses what the extranet
    partners think they are going to connect with. That being said, you can
    pretty much pick any RFC1918 address space at that point and use it in a
    similar fashion. The obvious alternative is that someone will need to change
    their address space.

    More detailed design you will probably have to pay me for. :-)

    One thing that this scenario really graphically depicts is why separation of
    resources is such a valuable objective. Sure, it sounds really nice to have
    all your stuff running on a mainframe running Linux hosts but these are the
    kinds of security problems you will then run into. (feel free to expand this
    statement as you see fit - i.e. integrated firewall/ids/content filter/spam
    control/virus scanning or separate switches vs. VLANs).

    HTH

    Wes Noonan
    mailinglists@wjnconsulting.com
    http://www.wjnconsulting.com
    Hardening Network Infrastructure - A concise how to guide
    Available Spring 2004
    Order at http://tinyurl.com/2nof4

    _______________________________________________
    firewall-wizards mailing list
    firewall-wizards@honor.icsalabs.com
    http://honor.icsalabs.com/mailman/listinfo/firewall-wizards


  • Next message: Bob Alberti: "RE: [fw-wiz] Sources for Extranet Designs?"

    Relevant Pages

    • Re: Peer to peer wifi setup
      ... >desktop shows all its shared resources and the laptop in My Network Places; ... Permanently disable the XP HE SP1 Internet Connection Firewall on ... Windows XP Network Protocols ...
      (microsoft.public.windowsxp.network_web)
    • RE: [fw-wiz] Sources for Extranet Designs?
      ... with allowing extranet partners access resources on my internal network. ... Connections are allowed to a group of web servers, ...
      (Firewall-Wizards)
    • Re: proper naming of a domain
      ... The primary reason for not being able to see resources/browse etc during a VPN is that the IPschema of remote network is the same as the LAN that you are connecting to. ... from home I can Connect to the server and it tells me that I am connect to ... resources it tells me that the path cannot be found. ...
      (microsoft.public.windows.server.sbs)
    • Re: Detect open windows shares?
      ... to know their names is to browse the network neighborhood. ... The WNetOpenEnum function starts an enumeration of network resources or existing connections. ... RESOURCE_CONTEXT Enumerate only resources in the network context of the caller. ... To obtain a description of the error, call the WNetGetLastError function. ...
      (comp.lang.perl.misc)
    • Re: Is Windows Firewall Blocking access
      ... but his Windows XP firewall is not protecting your corporate resources. ... inside the corporate network, ...
      (microsoft.public.windowsxp.general)