home *** CD-ROM | disk | FTP | other *** search
- Path: sparky!uunet!think.com!ames!lll-winken!gauss.llnl.gov!casey
- From: casey@gauss.llnl.gov (Casey Leedom)
- Newsgroups: comp.protocols.tcp-ip
- Subject: Re: Is the Balkanization of the InterNet inevitable?
- Keywords: security, firewalls
- Message-ID: <142173@lll-winken.LLNL.GOV>
- Date: 23 Nov 92 05:36:49 GMT
- References: <141672@lll-winken.LLNL.GOV>
- Sender: usenet@lll-winken.LLNL.GOV
- Organization: Lawrence Livermore National Laboratory
- Lines: 31
- Nntp-Posting-Host: gauss.llnl.gov
-
-
- Well, I've received several replies regarding my unhappiness with
- network firewalls. They fall into the following categories:
-
- 1. I'd rather protect one machine than the ten-thousand behind it.
-
- 2. So what are the [lauded] services are you missing?
-
- 3. Don't worry. Firewalls aren't as bad in general as the one you're
- living behind.
-
- The third item answers the second to some extent. The firewall I have
- to deal with only supports outgoing telnet and ftp sessions via a set of
- utilities apparently fronted by Sun: itelnet and iftp. These work by
- routing their outgoing connections through proxy servers on a machine
- which is allowed to access the outside world and is also exposed to it.
- The only incoming connection arrangement is via a separate machine which
- only allows telnet connections. Mail is MX'ed up the wazoo. I'm not
- sure how News is handled. (I don't know because I don't use the systems
- behind the firewall. I maintain my home on GAUSS.LLNL.GOV and do all my
- outside communication from here because I can avoid the firewall and it's
- hassles.) One of my biggest gripes is that we only have itelnet and iftp
- clients for Suns. This leads to seemingly endless multi-hop store and
- forward ftp acts guaranteed to try your patience.
-
- I suppose I should subscribe to the firewalls mailing list suggested by
- Robert K. Stodola in order to determine just how bad the situation is in
- general. So I'll study up on what the ``state-of-the-art'' is and return
- to flame later ... :-)
-
- Casey
-