Re: [fw-wiz] Firewall Primitives
From: George Capehart (capegeo@opengroup.org)
Date: 11/04/02
- Next message: Victoria of Borg: "Re: [fw-wiz] Firewall Primitives"
- Previous message: Paul Robertson: "[fw-wiz] QoS and P2P?"
- In reply to: Marcus J. Ranum: "Re: [fw-wiz] Firewall Primitives"
- Next in thread: Victoria of Borg: "Re: [fw-wiz] Firewall Primitives"
- Reply: Victoria of Borg: "Re: [fw-wiz] Firewall Primitives"
- Reply: Crispin Cowan: "Re: [fw-wiz] Firewall Primitives"
- Messages sorted by: [ date ] [ thread ] [ subject ] [ author ] [ attachment ]
From: George Capehart <capegeo@opengroup.org> To: "Marcus J. Ranum" <mjr@ranum.com> Date: Mon Nov 4 20:51:01 2002
"Marcus J. Ranum" wrote:
>
> David Lang wrote:
> >this is only close to complete if you define a firewall as a packet filter
> >of some sort.
>
> Excellent point. I submit for your consideration the observation
> that firewall primitives should _all_ be connection-oriented. For
> services that are not inherently connection-based, an effective
> firewall should simulate connections to the best of its ability.
>
> >even if you tried to extend the type to include things like HTTP/FTP/etc
> >you still will need other parameters to configure the proxies.
>
> I also suggest you consider firewall primitives should include
> content searching - either on originated or returned content,
> as well as vectoring to a VPN or trusted interface. Possibly
> also include primitives for redirecting traffic and possibly
> simulating a session start, so the firewall can interact
> effectively with things like honeyd.
This is interesting. So, a firewall really should/could/might be a
multi-layer, multi-protocol switch . . .
- Next message: Victoria of Borg: "Re: [fw-wiz] Firewall Primitives"
- Previous message: Paul Robertson: "[fw-wiz] QoS and P2P?"
- In reply to: Marcus J. Ranum: "Re: [fw-wiz] Firewall Primitives"
- Next in thread: Victoria of Borg: "Re: [fw-wiz] Firewall Primitives"
- Reply: Victoria of Borg: "Re: [fw-wiz] Firewall Primitives"
- Reply: Crispin Cowan: "Re: [fw-wiz] Firewall Primitives"
- Messages sorted by: [ date ] [ thread ] [ subject ] [ author ] [ attachment ]
Relevant Pages
|