Okay, I've been asked to create a tunnel between my network and a partner companies network. In a stroke of brilliance they used a network for their private lan they just pulled out of the air: 218.1.1.0
I've got the tunnel established, but I've not opened any ports to allow traffic. My concern is that not only will they be able to communicate with my servers, but so will whoever really owns those IP's. The ip of their citrix server is actually owned by a company in Korea. The chances of me getting them to renumber their network are slim to nil and the chances of me refusing to set it up and still keeping my job are definatly nil.
So my plan is to just mitigate the danger with a internal -> citrix -> 218.1.1.?? that just points to their citrix server and a 218.1.1.?? -> terminal services -> my termserv that just allow incoming traffic from a select few of their workstation.
Am I overreacting here? Any suggestions on how to mitigate this further?
This thread was automatically locked due to age.