[c-nsp] Telnet FROM a PIX Appliance?

Christian Koch christian at broknrobot.com
Tue Jul 1 10:25:04 EDT 2008


there is no need to have a firewall be an ssh/telnet client, that is not a
firewall's purpose... if you want to source ssh/telnet from the same subnet
your firewall is on, build a  jump box/bastion host..IMO- no network device
is a place to be using a remote access protocol (telnet, ssh, rsh), no
matter a firewall, router, load balancer, whatever...

there is just no reason for it, it just leaves another method of access to
your infrastructure in the case your device gets compromised

-christian


More information about the cisco-nsp mailing list