Re: [fw-wiz] IPTables QUEUE target equivalency in other firewalls

From: John Dorsey (dorsey@colquitt.org)
Date: 02/27/03

  • Next message: svyato slav: "[fw-wiz] Re: TCP/IP filtering concepts presentation"
    From: John Dorsey <dorsey@colquitt.org>
    To: firewall-wizards@honor.icsalabs.com
    Date: Thu, 27 Feb 2003 08:37:49 -0600
    

    Rod,

    > Netfilter/IPTables supports a target of QUEUE which delivers packets to
    > a userspace interface where they can be modified,inspected etc. For
    [deletia]
    >
    > Do any other firewalls have a similar function? I am particularly
    > interested in ipFilter, ipfw, packetfilter, or PIX (I know PIX is highly
    > unlikely since it is more of a dedicated appliance).

            It's not exactly the same, but the PIX has a 'capture' feature
    that lets you collect packets that match an acl, and view a summary or
    offload elsewhere. I think it exports pcap format; I usually just
    inspect them online. You can't modify packets with it.

            I don't know any way to automate it without 'expect' or
    equivalent.

    > Thanks for the information.

            yw.

    Cheers,
    John Dorsey

    _______________________________________________
    firewall-wizards mailing list
    firewall-wizards@honor.icsalabs.com
    http://honor.icsalabs.com/mailman/listinfo/firewall-wizards



    Relevant Pages

    • RE: [fw-wiz] Odd PIX / router behavior
      ... When you saw the original spoofed traffic, what kind of packets were ... My first thought was a misconfigured internal host too, ... 10.0.0.1 is the inside interface of the PIX. ...
      (Firewall-Wizards)
    • SV: Firewall Basics
      ... based firewalls since having two PIX firewalls would leave you vulnerable to ... the same exploits if a hole in PIX was found. ... to facilitate one-on-one interaction with one of our expert instructors. ... Attend a course taught by an expert instructor with years of in-the-field ...
      (Security-Basics)
    • RE: Routers, Switches, and Firewall testing
      ... We have been using the ISIC tool suite. ... random packets of the target protocol. ... specify the source and destination port along with the IP. ... While the test above is not "realistic" as firewalls generally do not recive ...
      (Pen-Test)
    • Re: Stateful Inspection
      ... >> A stateful firewall can inspect the contents of the packets as well. ... > VisNetic Firewall falls into a class of firewalls called Stateful ... Stateful inspection firewalls overcome the ...
      (comp.security.firewalls)
    • Re: Stateful Inspection
      ... >> A stateful firewall can inspect the contents of the packets as well. ... > VisNetic Firewall falls into a class of firewalls called Stateful ... Stateful inspection firewalls overcome the ...
      (comp.security.firewalls)