Re: DNS Names for external services

"Paul D. Robertson" <[email protected]> Tue, 27 Apr 2010 18:07:30 -0400 (EDT)
Newsgroups gmane.comp.security.firewalls.wizards
Message-ID <[email protected]>
On Mon, 26 Apr 2010, Morty Abzug wrote:

> Re-read above.  GP advocated setting up a honeypot on well-known names
> that *blocks* the source IP.  The problem with this is that if
> $legit_user of your company/organization says 'hey, I see
> "ftp.$mycompany.com" resolves' and tries it, you will block
> $legit_user's source IP.
> 

That's not a problem in my book.  Now perhaps your acceptable usage policy 
allows users to connect to anything they can dream up- but every single 
one I've ever written says what resources my users can use, and if they're 
on a fishing trip and they get shut out, then I'm not going to lose any 
sleep over it.

Paul
-----------------------------------------------------------------------------
Paul D. Robertson      "My statements in this message are personal opinions
[email protected]       which may have no basis whatsoever in fact."
           Moderator: Firewall-Wizards mailing list
           Art: http://PaulDRobertson.imagekind.com/