Security and Need for Firewalls

Damian Dunphy ( damian@sunbeach.net )
Thu, 31 Jul 1997 17:37:35 -0400

A request has been made of us as to how secure the following scenario would
be :

A dedicated internet connection to using a Compatible systems microrouter
that is hooked up to an internal network. Their file servers (1) NT 4.0 and
(1) Novell server would be configured to run Netbui only and IPX/SPX only.

The workstations are win95 and win3.11 and would run TCP/IP, Netbeui and
IPX/SPX and could hence communicate with the Internet and with both servers.

IS THERE A POTENTIAL RISK TO THESE SERVERS IF THEY WERE TO PUT THIS IN PLACE.

Could someone hack a workstation and somehow access the servers.

They want to put up a NT Box running only TCP/IP to serve as their mail
server and a public ftp site and propose running Post Office and IIS.

Should they consider implementing a fire wall or is protocol isolation for
the servers sufficient.

Any Ideas appreciated.