Unlabeled Hosts

How can I connect to a single unlabeled host (a MS Windows box) from multiple labels?

I have tsol setup with several compartments at the same sensitivity level. There is a MS Windows box on the network containing services that users from all compartments at this level need to connect to. I've tried various configurations with tnrhdb for this windows box specifying different templates including tsol and the sensitivity level without any compartment info, but nothing seems to let every compartment connect to the windows box.

Our answer up to now has been to assign several virtual IP addresses to the MS Windows box and then specify a different template for each IP in the tnrhdb file. This sort of works, but we have run into issues where we really need to get back to just using the primary IP on the MS Windows box.

Is there any way I can connect to this MS Windows box from every compartment at a single sensitivity level using just a single IP address on the MS Windows box?

[1017 byte] By [Ben] at [2007-11-25 23:04:19]
# 1

you need to open your interface to be somthing like ADMIN_HIGH to ADMIN_LOW and then the unlabled windows computer template also need to be ADMIN_HIGH to ADMIN_LOW.

If possible it might be better to put anouther network card in the computer and open it up only for the windows box.

Perry at 2007-7-5 17:55:59 > top of Java-index,General,Sun Alert and Security Discussion...
# 2
I would believe you would be able to add a new security family with the labels you wanted assigned to the family and then assign you host to that security family and the easiest way to accomplish I think is SMC.
eric3smith at 2007-7-5 17:55:59 > top of Java-index,General,Sun Alert and Security Discussion...