AW: Securing Web access from internet

From: Meidinger Chris (chris.meidinger_at_badenit.de)
Date: 08/07/03

  • Next message: STOJICEVIC E InfoEdpRsa: "RE : Linux security"
    To: "'gillettdavid@fhda.edu'" <gillettdavid@fhda.edu>, 'Bob Freeman' <cm94@hotmail.com>, security-basics@securityfocus.com
    Date: Thu, 7 Aug 2003 08:48:57 +0100 
    
    

    I agree, authenticating on the firewall is the best way to go.
    checkpoint fw-1 and rsa secureid work great together too for this.

    badenIT GmbH
    System Support
     
    Chris Meidinger
    Tullastrasse 70
    79108 Freiburg

    ______________

    Es gibt 10 arten von Menschen auf dem Planeten,
    welche die Binär verstehen, und welche die es nicht tun.

    -----Ursprüngliche Nachricht-----
    Von: David Gillett [mailto:gillettdavid@fhda.edu]
    Gesendet: Wednesday, August 06, 2003 10:57 PM
    An: 'Bob Freeman'; security-basics@securityfocus.com
    Betreff: RE: Securing Web access from internet

      Years back, I worked on a network where we had a requirement
    like this, which we met by deploying a PIX as gateway with an
    attached TACACS+ server. Clients who telnetted to the gateway
    and authenticated against TACACS+ got access to the network
    beyond the gateway.
      More recently, I've been using some of the authentication
    services offered by CheckPoint's FW-1 firewall and BlueSocket's
    "wireless" security box. I suspect that user authentication
    as a firewall feature has become fairly widespread, although
    I'm not sure how common on boxes costing less than about $10K.

    David Gillett

    > -----Original Message-----
    > From: Bob Freeman [mailto:cm94@hotmail.com]
    > Sent: August 6, 2003 08:58
    > To: security-basics@securityfocus.com
    > Subject: Securing Web access from internet
    >
    >
    >
    >
    > Hi everyone, We have a web application on our LAN (based on
    > IIS) and we want to make this web application available from
    > the internet for specific users/workstation. 1)I want to
    > make sure that these users/workstation are authenticated
    > BEFORE accessing the local network. 2)I want to make sure
    > that the information transiting on the public network is
    > encrypted 3)I would prefer to not have anything to install
    > on the remote workstations (if possible) 4)I don't want a
    > VPN solution. I don't know much about the product I need but
    > I suppose it would be a kind of web relay/authentication
    > server installed in our DMZ. Do you have product to
    > propose? Thanks Bob Freeman
    >
    > --------------------------------------------------------------
    > -------------
    > --------------------------------------------------------------
    > --------------
    >

    ---------------------------------------------------------------------------
    ----------------------------------------------------------------------------

    ---------------------------------------------------------------------------
    ----------------------------------------------------------------------------


  • Next message: STOJICEVIC E InfoEdpRsa: "RE : Linux security"

    Relevant Pages

    • Re: Outlook using RPC over HTTPS does not authenticate using the Kerberos Realm
      ... Used Outlook in Safe Mode, ... For testing, client and server are on the same network, so no proxy server. ... Please first select "Integrated Windows Authentication" on the PRC virtual ... Disable firewall or antivirus on PC, ...
      (microsoft.public.exchange.admin)
    • Re: need help to answer firewall question......
      ... Checkpoint is a fine firewall and supports a fairly large number of ... authentication methods, so if Checkpoint can't do what your boss is asking ... Increasing security is a tradeoff with reducing convenience and in some ... The firewall does "authenticate" successful connections to your servers by ...
      (comp.security.firewalls)
    • Re: IM Programs
      ... authentication part of it). ... I HATE INSTANT MESSENGERS. ... > It is virtually impossible to block them with a firewall. ... > and access one of the main MSN pages. ...
      (Security-Basics)
    • PPTP Routing Cisco 1841
      ... aaa authentication ppp default group radius local ... ip inspect name firewall tcp ... ip nat inside ... encapsulation aal5mux ppp dialer ...
      (comp.dcom.sys.cisco)
    • Re: Firewall with one-time passwords?
      ... All the authentication does is to tell the firewall allow ... Your one-time password has to be machine-generated, ... > stolen laptop with an unencrypted private key is a free ticket. ...
      (comp.security.firewalls)