Advanced Security Question
From: Hammer (hammeraus001_at_yahoo.com)
Date: 08/12/04
- Previous message: Dr. Robert Meier: "Re: GPG setup"
- Next in thread: Colin McKinnon: "Re: Advanced Security Question"
- Reply: Colin McKinnon: "Re: Advanced Security Question"
- Reply: Alexander Clouter: "Re: Advanced Security Question"
- Reply: Abdullah Ramazanoglu: "Re: Advanced Security Question"
- Reply: Dale Dellutri: "Re: Advanced Security Question"
- Reply: Skylar Thompson: "Re: Advanced Security Question"
- Messages sorted by: [ date ] [ thread ] [ subject ] [ author ] [ attachment ]
Date: 11 Aug 2004 18:20:52 -0700
Please forgive me if this is either a stupid question or will only be
available sometime in the late 24th century. Here goes...
Does anyone know how I would set a switched network to direct ALL
traffic through a linux box for authorisation, authentication, IDS and
logging. I could use RADIUS, but I've heard there are some flaws with
it.
Basically this box is going to check every packet on the network, log
it, check for "unwanted" activity and/or authorise it. It's going to
be acting in a super cop role, between clients, secure servers,
unsecure servers and Internet connection via firewall. Yes - it's a
firewall and DMZ, but to a greater extent.
I want any new machines to be denied access to anything until they are
authorised. I also want to stop all traffic between clients, unless
through the linux box.
Would IP tables on clients, servers and linux authentication box be
able to do this? Client Ip tables only allow traffic to
authentication server. Server Ip tables only allow traffic between
authorised servers and authentication server. Authentication server
only allow authorised traffic between itself and client/servers
(server traffic dependant upon server role). This sounds logical, but
could it be done?
Hammer
- Previous message: Dr. Robert Meier: "Re: GPG setup"
- Next in thread: Colin McKinnon: "Re: Advanced Security Question"
- Reply: Colin McKinnon: "Re: Advanced Security Question"
- Reply: Alexander Clouter: "Re: Advanced Security Question"
- Reply: Abdullah Ramazanoglu: "Re: Advanced Security Question"
- Reply: Dale Dellutri: "Re: Advanced Security Question"
- Reply: Skylar Thompson: "Re: Advanced Security Question"
- Messages sorted by: [ date ] [ thread ] [ subject ] [ author ] [ attachment ]
Relevant Pages
|