>The real problem is actually, not an architectural one.
>
>Security standards dictate that no device, no matter what its function, span
>2 networks of differing security domains.  This is an attempt to see if
>there was a way we could safely work around this.
>
>The hosts on the network segment to be scanned are not considered hostile,
>but since they are in a lower security domain, we need to technically
>consider them hostile, to consider them as if they had been compromised.
>
>Other than ipchains\iptables firewalling, any other suggestions?

Two machines? Probe thru the firewall, altho ACL's might get in the way? Or 
run "ifdown eth1 ; ifup eth0" before scanning?

Rob Nelson
[EMAIL PROTECTED]

Reply via email to