On Tue, 9 Jul 2024 at 23:40, Keith Moore <moore@xxxxxxxxxxxxxxxxxxxx> wrote:
On 7/9/24 18:29, Phillip Hallam-Baker wrote:
> One of the weaknesses of the Internet architectural model as insisted
> upon by many here is that insisting 'anything can talk to anything'
> makes it really hard to secure file servers locking them to only be
> visible to the local network.
Why should "the local network" (as a collection of hardware) be
meaningful at all?
As Brian hints, Phillip mis-spelt "local security domain".
I do remember when network location was a pretty good proxy for security domain. That is, in part, what NAT is trying to maintain, I think.
Dave.