Building Your Own Data Diode with Open Source Solutions
blog.cimation.com
blog.cimation.com
You'll need to encapsulate the traffic in a one way protocol and fake the responses required by higher level two way protocols on either side. Also disconnecting one fiber, will result in a link down/no carrier link state with default networking drivers, so some patches are needed in this area. Love to see some open source software capable of this.
Replication might be infeasible, but file transfer works. Developed specially for use with data diodes: BlindFTP - http://adullact.net/projects/blindftp/ (French site, but there is a download link at http://adullact.net/frs/download.php/file/5406/BlindFTP_0.37...)
[1] http://blog.cimation.com/blog/data-diodes-and-security-in-th...
More here: https://en.wikipedia.org/wiki/Autonegotiation
You may be able to disable this feature, but it comes at great cost of losing link monitoring.
Without bi-directional replication, there's no way of stopping replication during failure, or inducing back pressure.
I'm inclined to think that this is a joke of some kind? I don't know.
https://en.m.wikipedia.org/wiki/Unidirectional_network
http://www.owlcti.com/pdfs/whitepapers/All_Diodes_Are_Not_Eq...
Furthermore, you can implement a certifiably low-risk system for retransmits using a separate ultra-low-bandwidth uplink that can raise a NACK on data errors that FEC can't handle. This is sufficient for unidirectional TCP streams to be wrapped.
I mean, sure, you can fake it if you're not worried about someone connecting the wrong cable (potentially turning your system into a wonderful fountain of all the data you were trying to protect) and if you're willing to write custom application level protocols to handle significant amounts of data loss in transmission.
A few months ago I published a more detailed Whitepaper in the SANS reading room that provides a working data diode (using off the shelf parts) and PowerShell code that will transfer files unidirectionally as a proof of concept. https://www.sans.org/reading-room/whitepapers/firewalls/tact... It talks through the challenges of implementing a data diode on an OSI layer basis. I hope you enjoy it and I would love to hear your thoughts.
As others have mentioned TCP goes out the window immediately. Luckily for lots of applications sending updates work really well.
But more importantly -- fiber network cards have clearly physically separated transmitter and receiver ports. A transmitter port does not contain the hardware for receiving data, and the receiver port does not contain the hardware for transmitting.
A one-wire serial connection can (probably) be reversed by replacing the firmware of the controller chip. A one-way fiber connection as described in this article is physically incapable of transmitting data in the opposite direction.
Hehe, still fast enough to track thousands of commercial targets : )
Good points about physically incapable. Another thing fiber gives you is electrical insulation.
I would say; probably not. RS-232 uses fairly high positive and negative voltages. There is always some sort of driver that can't be made to work in reverse.