Re: Best security topology for FreeBSD

From: Crist J. Clark (cristjc@earthlink.net)
Date: 11/27/01


Date: Mon, 26 Nov 2001 17:05:04 -0800
From: "Crist J. Clark" <cristjc@earthlink.net>
To: Ahsan Ali <ahsan@khi.comsats.net.pk>

On Mon, Nov 27, 2000 at 12:12:06AM +0500, Ahsan Ali wrote:
> What would the ideal security model for an ISP with a lot of sites and
> services hosted be?

A traditional ISP does (and should do) almost no filtering between its
peer points and its clients. An ISP should protect its administrative
network (accounting, marketing, etc.) and external service servers
(SMTP, POP, HTTP, Radius, etc.) pretty much like any other large
business. Some of these, like a Radius server, are not really seen in
many other businesses and have different requirements (it is accepting
requests from ISP owned machines on ISP owned network, but the network
must be considered hostile since the customers have "raw" access to
it). In an ISP environment, you have to depend on hardening hosts a
lot more since many are required to operate in very insecure
environments.

And you might want to fix that clock of yours. Or you seem to be
existing in some kind of time warp.

-- 
Crist J. Clark                           cjclark@alum.mit.edu
To Unsubscribe: send mail to majordomo@FreeBSD.org
with "unsubscribe freebsd-security" in the body of the message


Relevant Pages

  • RE: multiple uplinks from ISP
    ... Getting VMware network to network can be hard. ... I think he knows a lot about multipath routing with or without quagga. ... Subject: multiple uplinks from ISP ...
    (freebsd-net)
  • Re: multiple uplinks from ISP
    ... machines for building a test network, in other words I cannot do experiments ... Subject: multiple uplinks from ISP ... What you need is two machines with 3 interfaces each. ...
    (freebsd-net)
  • Rh 9 Modem Connection Problem
    ... I have a problem with connecting to my ISP with RH 9 and it is driving me ... Network tool, I keep getting the error messages "Can not activate network ... adapter, add modem adapter, did the whole lot again by deleting the modem ... Feb 29 07:06:02 localhost wvdial: Initializing modem. ...
    (linux.redhat.misc)
  • Rh 9 Modem Connection Problem
    ... I have a problem with connecting to my ISP with RH 9 and it is driving me ... Network tool, I keep getting the error messages "Can not activate network ... adapter, add modem adapter, did the whole lot again by deleting the modem ... Feb 29 07:06:02 localhost wvdial: Initializing modem. ...
    (linux.redhat.install)
  • Re: Help needed on ip forwarding
    ... >> Here's my current network. ... >> My modem gets an external IP from the ISP. ... >> external IP address on the virtual interface (I have two physical ... > PORTS, not IPs. ...
    (comp.os.linux.networking)

Quantcast