Re: LAN access while VPN is up

From: Triffid (triffid_at_nebula.net)
Date: 11/03/05


Date: Wed, 02 Nov 2005 20:31:17 -0500


Somebody. wrote:

> "Triffid" <triffid@nebula.net> wrote in message
> news:Eucaf.5510$LF3.626347@news20.bellglobal.com...
>
>>
>>Somebody. wrote:
>>NS says:
>>
>>"The Work and Home zones allow you to segregate users and resources in
>>each zone. In this mode, default policies allow traffic flow and
>>connections from the Work zone to the Home zone, but do not allow traffic
>>from the Home zone to the Work zone".
>>
>>I understood you have full control of work -> home policy, but cannot
>>create home -> work policy. That would meet my needs, are you saying it's
>>not the case?
>
>
> I'm saying we tricked a NS into breaking that principle, but in a normal
> configuration, you won't likely see that happen. So, forget I said
> anything. :-)

Not likely - I don't let things like that slide, as they are frequently
indicative of a design issue that will bite you in other ways. Did you
open a case?

>>>However I've found a far more flexible option is to put in a FG60 for
>>>folks working at home with kids. You have separate interfaces (internal,
>>>DMZ, WAN1, WAN2) that can be arbitrarily configured any way you like (add
>>>in VLANS if you want to get crazy with zones) with total control over all
>>>traffic between all zones with mulitple site-to-site VPNS. You can even
>>>block porn and other nefarious sites for the kids, AV all your mail and
>>>browse traffic, block whatever IMs you want, and put IPS on the works,
>>>block some adware, and log and track all the kids browse and email
>>>traffic. For around $1K for hardware and the first year of
>>>subscriptions.
>>
>>At roughly 4x what I have invested in the Netscreen, I would certainly
>>expect far more flexibility :-) However, I have my eye on a pair of 208s
>>that are likely to be swapped out soon...
>>
>>Triffid
>
>
> Well if you're comparing used hardware without support against new hardware
> with support and AV/IPS/SPAM/filtering subscriptions, that might account for
> the price difference. :-)

I'm not - my 5GT was new when I bought it on eBay, and I was able to
negotiate support and subscriptions for it at very reasonable rates in
conjunction with a hardware order. Sure I had leverage not available to
all, but the bottom line is just that...

> 208s are very nice boxes, just don't expect to do any Deep Inspection with
> them. Stateful packet inspection only.

No? Not supported, or not enough horsepower? (I don't 'own' any 208s at
work, so don't have much experience with them)

Triffid



Relevant Pages

  • Re: Speeding fines doubled when workers present
    ... construction area. ... 370, which has road construction at the moment, but it didn't appear ... a zone defined and work in that zone means ... marked as a Work Zone means that the work zone laws apply, ...
    (misc.transport.road)
  • Re: Scary
    ... >where the speed limit should be enforced without tolerance, ... we see work zone speed limits in force when they ... limits if DOTs were careful to restrict speeds only when work is in ...
    (misc.transport.road)
  • Re: Solaris OS versions supported on the cool thread series
    ... then pkgadd in the global zone won't work becaus it claims a pkgadd ... so I need 100x better MTBF on the hardware to keep the ... same MTBF on my application. ...
    (comp.sys.sun.hardware)
  • Re: 1.10 Rez bug
    ... I wonder if their application is monolithic for a zone... ... the hundreds of players in Kalimdor have to share a piece of hardware. ... servers. ... Kalimdor and instances were unaffected. ...
    (alt.games.warcraft)
  • Re: AIX vs Solaris
    ... AIX's virtualisation has been proven for a number of years and is hardware ... where as Suns offering of zone is relatively new and Domains are not ...
    (comp.sys.sun.admin)

Quantcast