OSEC

Neohapsis is currently accepting applications for employment. For more information, please visit our website www.neohapsis.com or email hr@neohapsis.com
 
Subject: Re: Simple Pimple firewalls
From: Marcus J. Ranum (mjrnfr.com)
Date: Mon Dec 04 2000 - 18:58:46 CST


"Roy G. Culley" <tgdcuro1gd2.swissptt.ch> writes:
>What about normal ftp (not PASV), IIOP, net-meeting, sun-rpc, etc?
>Keeping state is necessary if you are to have any chance of allowing
>these without opening up huge holes in your firewall.

If you're allowing those, you've opened up huge holes
in your firewall by virtue of the fact that you're allowing
them. Stateful inspection versus non-stateful inspection
is a non-issue if the protocols you're letting back and
forth are more toxic than a fist full of Ebola.

mjr.

---
Marcus J. Ranum, Chief Technology Officer, NFR Security, Inc.
Work:	http://www.nfr.com
Play: http://www.ranum.com

- [To unsubscribe, send mail to majordomolists.gnac.net with "unsubscribe firewalls" in the body of the message.]