Re: [fw-wiz] CERT vulnerability note VU# 539363

From: Daniel Hartmeier (daniel@benzedrine.cx)
Date: 10/16/02


From: Daniel Hartmeier <daniel@benzedrine.cx>
To: Stephen Gill <gillsr@yahoo.com>
Date: Wed Oct 16 09:53:00 2002

On Wed, Oct 16, 2002 at 08:20:09AM -0500, Stephen Gill wrote:

> In my opinion if a stateful firewall claims it can filter at rate X
> (64byte packets, etc...), it should be able to filter at that rate under
> all conditions.

Obviously, for any X, when each packet is part of a TCP handshake, the
X/2 (or /3, depending on how you count) newly established connections per
second will exhaust memory on the firewall after a certain amount of time.

I don't think you meant 'be able to filter at that rate' to include
'dropping legitimate connections when running out of memory', did you?

> I'd like to learn some of the other methods being used for mitigation
> amongst vendors.

Yes, that's what I'd find most intersting to read in vendor statements
myself. :)

Daniel



Relevant Pages

  • Re: [fw-wiz] CERT vulnerability note VU# 539363
    ... >> In my opinion if a stateful firewall claims it can filter at rate X ... > 'dropping legitimate connections when running out of memory', ... >> amongst vendors. ...
    (Firewall-Wizards)
  • Re: How to set NIC to promiscuous mode from FilterHook driver
    ... So from your reply I take it you are interested in getting packets destined to other hosts -that are not necessarily originated from the host your filter is running on-. ... As I said in my previous post, setting the adapter to promiscuous mode is not going to help you. ... the filter hook driver I mentioned is as per the msdn ...
    (microsoft.public.development.device.drivers)
  • Re: Req: info on IP range popup ad software supposedly called "Extreme Marketing"
    ... forges packets for wndows dialup connections. ... I'd pick a switch that could filter on MAC and IP ... > that should be hooked up to that port. ...
    (comp.security.misc)
  • Re: PF, bridge, states and window scaling problem
    ... My problem comes with the filter rules. ... the bridge use TCP window scaling. ... but not matched by the rest of the packets ... statefull firewall has an unpredictable behaviour on bridges. ...
    (freebsd-questions)
  • Re: Comodo blocking port forwarding
    ... filter to drop every packets, how exactly would you try to circumvent this? ... As for a more practical example: I setup a packet filter to only allow HTTP ... Well, most you say about PFW, can be easily applied ...
    (comp.security.firewalls)