Xenophobic TCP gatewaying

James M. Turner turner at ksr.com
Fri Sep 21 09:56:03 AEST 1990


We're starting to look at the problem of securing a potential Internet
gateway.  Basically, the problem can be stated as such:

We want to be able to accept incoming mail and news, and make FTP requests
and logins to the net.  Other than that, we don't want ANY incoming or
outgoing traffic allowed.  In addition, we want to have verified and
absolutely secure versions of the daemons to be the ones we run.  We also
want to be able to make FTP requests from any machine on the local net,
but DO NOT want any packet from the outside to be able to pass the gateway
machine.

Has anyone attacked this problem to date, and if so, what recommendations
can you make?

Name:    James M. Turner          
Company: Kendall Square Research  
Email:   turner at ksr.com, ksr!turner
Phone:   (617) 895-9400           



More information about the Comp.sys.sun mailing list