Firewall Wizards mailing list archives

Question about vulnerabilty


From: "Robert Driscoll" <driscoll_r () primesource com>
Date: Thu, 5 Aug 1999 15:28:49 -0700


Hello,

        I am in the process of defining an internet security policy for my
company and I was wondering about the possible vulnerability of the
following
scenario.

        The main office is protected by a firewall, there are approx. 40 remote
offices connected via frame-relay (small offices @56K). We bring back their
internet traffic through our main firewall (NAT/Proxy Server), but it slows
down branch operations when someone is hitting the 'net.

        Several of my offices are requesting local internet connections.

        So the question is:

        If the local office offers no services, (No sendmail, DNS, WebSite etc.)
out
the local internet connection. What vulnerabilities exist for this scenario?
We
are using an unroutable address (10.x.x.x) internally. I guess telneting
into the
local router and hacking that way. (Possible IP Spoofing?)

        Any suggesions?

        Thanks!



Current thread: