Re: [fw-wiz] VPNmadness gets more support;

From: George Capehart (capegeo_at_opengroup.org)
Date: 02/13/05

  • Next message: ArkanoiD: "Re: [fw-wiz] smtp proxy on firewall"
    To: "Paul D. Robertson" <paul@compuwar.net>
    Date: Sat, 12 Feb 2005 18:45:01 -0500
    
    

    Paul D. Robertson wrote:

    <snip>

    >
    > "Don't connect" isn't pure drivel, it's the first consideration you should
    > make. There is no reason that many operational infrastructure networks,
    > like parts of the power grid need to be susceptible to worm traffic when
    > they're mostly composed of production embedded systems.

    Amen! See this thread on nanog . . . but it's about ATMs . . . ;> :

    http://www.cctec.com/maillists/nanog/historical/0301/msg00769.html

    <snip>

    >
    > Along with blanket deployments where VPN access == full network access.
    >
    > Client to network VPNs should almost always limit access. </blanket
    > statement>

    Yes! See above for what happens when VPNs aren't terminated into a DMZ
    . . .

    Cheers,

    George Capehart

    --
    "With sufficient thrust, pigs fly just fine . . ."  -- RFC 1925
    _______________________________________________
    firewall-wizards mailing list
    firewall-wizards@honor.icsalabs.com
    http://honor.icsalabs.com/mailman/listinfo/firewall-wizards
    

  • Next message: ArkanoiD: "Re: [fw-wiz] smtp proxy on firewall"

    Relevant Pages

    • Re: Other JSF options
      ... the point of firm positions of disagreement, so my comments below will be ... <snip stuff there is no use arguing further> ... Nor, AFAIR, did the GAO claim that the M60A3 was "inherently" a better tank ... And of course the reason, most of the reason for the current slip was the ...
      (rec.aviation.military)
    • Re: I know you guys would hate me for this....
      ... usually just snip them. ... the reason why we are responding to it, but merely responding for the sake ... of being sensitive to your cat. ... If Ranmao wants a hug, ...
      (rec.games.computer.ultima.dragons)
    • Re: OT:Thanksgiving
      ... tentative excuse, but not the reason. ... Our new government is founded upon exactly the opposite idea; ... the negro is not equal to the white man; that slavery - subordination to ...
      (comp.lang.cobol)
    • Re: This is absolutely GREAT!!!
      ... Randy, first you back off from one city. ...  That is the reason we have the mess we are in now. ...   you don't like that. ...
      (misc.transport.road)
    • Re: Javascript on the client as an alternative to Perl/PHP/Python on the server
      ... stored while the Internet connection is established and accessed later offline. ... requires CSS, image, JavaScript, Flash, Quicktime support etc. ... I included "not so sophisticated" for a reason. ...
      (comp.lang.javascript)

    Loading