Firewall Wizards mailing list archives

Re: securing X.25 connection


From: Adam Shostack <adam () weathership homeport org>
Date: Sun, 9 Aug 1998 13:34:13 -0400

On Mon, Aug 03, 1998 at 09:46:11AM -0400, Ted Doty wrote:
At 11:24 AM 7/30/98 +0800, g  wrote:

I have a requirement to connect our internal system (IP based) to a data
feed  through a X.25 connection. Any advise on how to secure this X.25
connection?

First step should be to collect all the addresses you're willing to accept
X.25 calls from.  Hard code these into the config (your router should allow
you to do this).  This will at least limit access to known sources.

The next question to ask is how much you trust those sources.  If they are
remote offices of your organization, you might be good to go.  If they're
other organizations, you'll probably want some kind of firewall (more
specifically, *I'd* want a firewall; your mileage may vary).

        I'm not an X.25 expert by any stretch, but let me ask if X.25
addresses are analogous to IP addresses, ie, easily spoofed?  My
impression of the X.25 network (from places like the Austriallian book 
"Underground"), is that its wide open, and providers don't do source
filtering.

Adam



Current thread: