Re: is manual keying mandatory (fwd)

Robert Moskowitz <rgm-sec@htt-consult.com> Thu, 19 March 1998 18:25 UTC

Received: (from majordom@localhost) by portal.ex.tis.com (8.8.2/8.8.2) id NAA20014 for ipsec-outgoing; Thu, 19 Mar 1998 13:25:39 -0500 (EST)
Message-Id: <3.0.5.32.19980319133415.0099ed20@homebase.htt-consult.com>
X-Sender: rgm-sec@homebase.htt-consult.com
X-Mailer: QUALCOMM Windows Eudora Pro Version 3.0.5 (32)
Date: Thu, 19 Mar 1998 13:34:15 -0500
To: Paul Koning <pkoning@xedia.com>, perry@piermont.com
From: Robert Moskowitz <rgm-sec@htt-consult.com>
Subject: Re: is manual keying mandatory (fwd)
Cc: jhwilson@austin.ibm.com, ipsec@tis.com
In-Reply-To: <9803191616.AA00927@kona.>
References: <199803190509.XAA26210@jhwilson.austin.ibm.com> <199803191421.JAA04709@jekyll.piermont.com>
Mime-Version: 1.0
Content-Type: text/plain; charset="us-ascii"
Sender: owner-ipsec@ex.tis.com
Precedence: bulk

At 11:16 AM 3/19/98 -0500, Paul Koning wrote:
>
>Consider ARP.  It's been around for decades... but people still
>support static ARP entries.

And it has worked out as a powerful tool to make sure that the only systems
working on your DMZ are the ones you put there.


Robert Moskowitz
ICSA
Security Interest EMail: rgm-sec@htt-consult.com