Re: [fw-wiz] Multicast Firewall

From: Marcus J. Ranum (mjr_at_ranum.com)
Date: 10/22/03

  • Next message: Wes Noonan: "RE: [fw-wiz] Clients cant access pix w/ vpn from behind nat devices using the newest cisco client."
    To: Ravi Kumar <ravivsn@roc.co.in>, firewall-wizards@honor.icsalabs.com
    Date: Wed, 22 Oct 2003 15:34:29 -0400
    
    

    Ravi Kumar wrote:
    >I was asked to prepare specifications for multicast firewall.

    Interesting problem!!! What are the security policy problems of a
    multicast message? Then work your way back from there. It has
    a source, right, but no destination? I'd argue that a multicast
    firewall should be able to *add* destination specifiers to match
    sources. So I'd like to be able to tell it "this service can be
    multicasted to these machines only" There's another question
    which is "what services, in a security conscious environment,
    make *sense* to multicast?" Start with those and then ask
    yourself what security controls you can add to them.

    Back when I was doing firewalls, that was the logic I followed:
    look at the overall communications problem and then figure out
    what security the firewall could *add* - on the assumption that
    everything lacked underlying security. Usually that's a good
    assumption.

    mjr.

    _______________________________________________
    firewall-wizards mailing list
    firewall-wizards@honor.icsalabs.com
    http://honor.icsalabs.com/mailman/listinfo/firewall-wizards


  • Next message: Wes Noonan: "RE: [fw-wiz] Clients cant access pix w/ vpn from behind nat devices using the newest cisco client."

    Relevant Pages

    • [REVS] Bypassing Client Application Protection Techniques
      ... Get your security news from a reliable source. ... protection programs. ... * Kerio Personal Firewall 4.0 ... And we got actually nothing in the field of client application ...
      (Securiteam)
    • Re: Recycler security issues on IIS server
      ... > latest upates to the server. ... > like to see the server put behind our firewall, ... other software, install all patches, IISlockdown, URLscan, use the correct ... the procedures you follow may vary depending on your security needs. ...
      (microsoft.public.inetserver.iis.security)
    • Why hasnt Symantec addressed nastier Messenger spoofs
      ... Norton / Symantec has been silent on whether Norton Internet Security ... DSL firewall will stop these kinds of pop-ups. ... major ISPs and broadband systems. ...
      (comp.security.misc)
    • Re:RE : suggestions on a good firewall
      ... Subject: RE: suggestions on a good firewall ... CheckPoint does! ... with a url-filtering server. ... IT Technical Security Officer ...
      (Security-Basics)
    • Re: What is the Pattern here ?
      ... These are all Dialup Connections that I had no connection with at the time. ... It's obviously an enormous security hole, ... > and a real firewall box. ...
      (comp.security.firewalls)