FirewallWizards
[Top] [All Lists]

Re: [fw-wiz] Communication Device Protocols from External router directt

To: Firewall Wizards Security Mailing List <firewall-wizards@listserv.icsalabs.com>
Subject: Re: [fw-wiz] Communication Device Protocols from External router directthrough Firewall
From: Frank Knobbe <frank@knobbe.us>
Date: Tue, 07 Nov 2006 11:10:53 -0600
Delivered-to: sp-com-lists@consult.net
Delivered-to: fwwizards-list2@consult.net
Delivered-to: firewall-wizards@listserv.cybertrust.com
In-reply-to: <7DA21FCA8AD4A94F9E77D3612F1A1A1301D54E5D@0307-its-exmb01.us.saic.com>
List-archive: <https://listserv.icsalabs.com/pipermail/firewall-wizards>
List-help: <mailto:firewall-wizards-request@listserv.icsalabs.com?subject=help>
List-id: Firewall Wizards Security Mailing List <firewall-wizards.listserv.icsalabs.com>
List-post: <mailto:firewall-wizards@listserv.icsalabs.com>
List-subscribe: <https://listserv.icsalabs.com/mailman/listinfo/firewall-wizards>, <mailto:firewall-wizards-request@listserv.icsalabs.com?subject=subscribe>
List-unsubscribe: <https://listserv.icsalabs.com/mailman/listinfo/firewall-wizards>, <mailto:firewall-wizards-request@listserv.icsalabs.com?subject=unsubscribe>
References: <7DA21FCA8AD4A94F9E77D3612F1A1A1301D54E5D@0307-its-exmb01.us.saic.com>
Reply-to: Firewall Wizards Security Mailing List <firewall-wizards@listserv.icsalabs.com>
Sender: firewall-wizards-bounces@listserv.icsalabs.com
On Wed, 2006-11-01 at 01:11 -0500, Horvath, Kevin M. wrote:
> [...], so now onto SSH.  SSH shouldnʼt be allowed as this should only
> be done via your LAN (specifically a an ADMIN VLAN or better yet an
> OOB connection) or over an IPSec tunnel.  Yes its encrypted once the
> tunnel from the client to the server has been built but why should you
> allow anyone to attempt to make this connection externally?  Itʼs a
> recipe for disaster.  So even if you filter by source IP then there is
> the potential to be spoofed and then if you are running an older
> version of SSH that is vulnerable to a remote exploit you are sunk.  

While I agree with most of your post, I don't think the last statement
is valid. I could counter that you should never let IPsec in from the
outside, especially since the disclosure of the more IPSec flaws not too
long ago. Why would you want to expose your network like that?

SSH is a VPN protocol like others. It had flaws in the past, but so does
IPSec. So do other VPN protocols. There is no absolute security, which
I'm sure you know. SSH can be very safe on the Internet. Many words have
been written on secure SSH configurations, so I don't see a problem
using SSH as a VPN protocol. Personally, I'm more afraid of IPSec,
especially since everyone assumes it's safe when in reality it is not.

Regards,
Frank


-- 
It is said that the Internet is a public utility. As such, it is best
compared to a sewer. A big, fat pipe with a bunch of crap sloshing
against your ports.

Attachment: signature.asc
Description: This is a digitally signed message part

_______________________________________________
firewall-wizards mailing list
firewall-wizards@listserv.icsalabs.com
https://listserv.icsalabs.com/mailman/listinfo/firewall-wizards
<Prev in Thread] Current Thread [Next in Thread>