In addition to dial-in/dial-out connections, the use of Serial Line IP (SLIP) and Point-to-Point Protocol (PPP) connections need to be considered as part of the policy. Users could use SLIP or PPP to create new network connections into a site protected by a firewall. Such a connection is potentially a backdoor around the firewall, and may be an even larger backdoor than a simple dial-in connection.
Section provided several examples for locating dial-in capability such that dial-in connections would pass first through the firewall. This sort of arrangement could be used as well for SLIP and PPP connections, however this would need to be set forth in policy. As usual, the policy would have to be very strong with regard to these connections.