>The real problem is actually, not an architectural one. > >Security standards dictate that no device, no matter what its function, span >2 networks of differing security domains. This is an attempt to see if >there was a way we could safely work around this. > >The hosts on the network segment to be scanned are not considered hostile, >but since they are in a lower security domain, we need to technically >consider them hostile, to consider them as if they had been compromised. > >Other than ipchains\iptables firewalling, any other suggestions?
Two machines? Probe thru the firewall, altho ACL's might get in the way? Or run "ifdown eth1 ; ifup eth0" before scanning? Rob Nelson [EMAIL PROTECTED]
