Skip site navigation (1)Skip section navigation (2)
Date:      Wed, 1 May 1996 12:58:23 -0400 (EDT)
From:      Paul Danckaert <pauld@umbc.edu>
To:        Garth Kidd <garth@dogbert.systems.sa.gov.au>
Cc:        Mark Newton <newton@communica.com.au>, Kristyn Fayette <kristyn@gnu.ai.mit.edu>, freebsd-security@FreeBSD.org
Subject:   Re: FreeBSD & firewalls
Message-ID:  <Pine.SGI.3.91.960501125310.24442A-100000@umbc7.umbc.edu>
In-Reply-To: <960501101804.ZM2871@jolt.systems.sa.gov.au>

next in thread | previous in thread | raw e-mail | index | archive | help
On Wed, 1 May 1996, Garth Kidd wrote:

> On Apr 30, 10:02, Paul Danckaert wrote:
> 
> > Also, I'm just curious and haven't looked too much into it, but has 
> > anybody used BSD to firewall people within a site?  For example, we are 
> > looking at putting dorms on ethernet, but we are going to block various 
> > protocols, ports, etc..  
> 
> Great idea.  Those dorms are a real security threat, and I completely 
> understand wanting to firewall yourself off from them :).
> 
> [I'm at least a measure serious, actually; what are you trying to protect?]

Well, its really a minimal protection against IP spoofing, low level 
attacks, and for "policy enforcement".  (Ie: We don't want to become an 
ISP, so we restrict logins from modem pools, etc..)

I don't think we will have too many problems.. for example, I don't know
how many people in our dorms would do low level NFS guess attacks, or
anything like that.. but I would rather have something in place when we
wire them up and not use it much, than having to put something in a year 
after.. 

paul






Want to link to this message? Use this URL: <https://mail-archive.FreeBSD.org/cgi/mid.cgi?Pine.SGI.3.91.960501125310.24442A-100000>