[Search for users] [Overall Top Noters] [List of all Conferences] [Download this site]

Conference noted::seal

Title:SEAL
Moderator:GALVIA::SMITH
Created:Mon Mar 21 1994
Last Modified:Fri Jun 06 1997
Last Successful Update:Fri Jun 06 1997
Number of topics:1989
Total number of notes:8209

1782.0. "Generic Proxy for anonymous ftp & http: security?" by TENNIS::KAM (AltaVista Software 714/261-4133 DTN 535.4133) Fri Feb 07 1997 17:58

    One can use the Generic Proxy for both the AltaVista Firewall for Digital
    UNIX or Windows NT to allow "anonymous ftp" and/or "http".  What kind
    of security issue do you see around this?  Can't http allows ftp, etc?
    
    	Regards,
    
T.RTitleUserPersonal
Name
DateLines
1782.1QUICHE::PITTAlph a ha is better than no VAX!Wed Feb 12 1997 06:4822
What?  (Or pardon, as we make my son say instead of what? ...)

There is absolutely no way that the generic relay can handle ftp.  There never
will be such a way.  The problem with ftp is that it is a complex protocol, in
which the server makes a reverse connection to the client to handle any larger
amount of data, such as a file transfer.

We have one customer that has used the generic relay to handle http - he
insisted on having his public web servers on that internal network, and he uses
the generic relay to carry the traffic inside the firewall.  This particular
application, at least, is a mess, and I would strongly encourage any customer
away from this idea.

Both firewall products - indeed all the AltaVista firewall products (did you
know there are now 6 of them?) - have a WWW proxy that can handle outgoing http,
ftp, gopher, wais, https and snews requests from internal clients to external
servers.

What is the purpose of the question?  What are you trying to achieve?  That
would help us give a more specific answer ...

T
1782.2This is how I havw provided http and ftp to server on DMZNQOS01::tunsrv2-tunnel.imc.das.dec.com::KyleHow secure is it?Thu Feb 13 1997 10:2815
What I have done for a customer that has an anonymous ftp server on their 
public web server (on the DMZ net) is to use the generic relay for http and 
the ftp relay for ftp.  I created an internal (blue) server group with the 
web server as the only system in the group. I then added the following two 
lines to /usr/dfws/config/ftpxd-custom.acl:

  include "/usr/dfws/config/customgrps.acl";

  allow unknown inside red net ftp,gets,puts grpID;
   (where grpID is the id of the group defined in
    customgrps.acl)

We then added instructions in help_ftpxd.txt for the connection.

Bill
1782.3TENNIS::KAMAltaVista Software 714/261-4133 DTN 535.4133Mon Feb 17 1997 22:286
    re .1 
    Customer wants the Web Server and ftp Server on the Blue net.  I guess
    we'll hold this customer off until we have Green  Net support shortly.
    
    	Regards,
    
1782.4BIGUN::nessus.cao.dec.com::MayneWake up, time to dieTue Feb 18 1997 17:243
"Green net support shortly"?

PJDM
1782.5QUICHE::PITTAlph a ha is better than no VAX!Thu Feb 20 1997 12:105
We have always been told previously that Green Net was an NSIS (Digital
Consulting, Internet/Intranet Practice, or whatever ...) offering.  Has this
changed?

T