Re: [fw-wiz] Evolution of Firewalls

From: Christian Kreibich (christian_at_whoop.org)
Date: 03/10/04

  • Next message: Don Parker: "[fw-wiz] Is your IDS output really being checked?"
    To: Firewall Wizards <firewall-wizards@honor.icsalabs.com>
    Date: Tue, 09 Mar 2004 23:10:19 +0000
    
    

    On Tue, 2004-03-09 at 18:26, Dave Piscitello wrote:
    >
    > Emphasis on "functionality" not implementation, and "inspect all things
    > that ought to have their own port # but are now tunneled through port
    > 80"(primarily, not exclusively). May the "don't proliferate port number
    > assignment" gods forgive what I suggest here but I honestly don't think we
    > make life any easier by creating one gaping hole than several dozen
    > possibly containable ones.

    I recall a thread on this list in which the majority seemed to agree
    with this. It's from about a year ago (wow, I think I'm officially a
    long-time lurker now :) and also contains a nice discussion of the pros
    and cons of smoking:

    http://honor.icsalabs.com/pipermail/firewall-wizards/2003-April/014339.html

    Cheers,
    Christian.

    -- 
    ________________________________________________________________________
                                              http://www.cl.cam.ac.uk/~cpk25
                                                        http://www.whoop.org
    _______________________________________________
    firewall-wizards mailing list
    firewall-wizards@honor.icsalabs.com
    http://honor.icsalabs.com/mailman/listinfo/firewall-wizards
    

  • Next message: Don Parker: "[fw-wiz] Is your IDS output really being checked?"

    Relevant Pages

    • Re: OT New Orleans worth rebuilding?
      ... >> Shipping needs to go to a place below sea level? ... > If it's the Mississippi, the port really ought to be at a place where ...
      (rec.sport.football.college)
    • Re: Motorola 68k vs. Motorola 88k processors
      ... It was written by Tim Wescottin message ... > for the Power PC, so it won't be well supported. ... You ought to be able ... > to do a port, but I'm surprised there isn't one out there already. ...
      (sci.electronics.design)
    • Cant open OWA
      ... Re-run the CEICW and enable OWA as well as anything else you wish ... You ought to be using SSL and port 443, ...
      (microsoft.public.windows.server.sbs)
    • Re: help with sendmail
      ... There are security holes in that version: you ought to upgrade to the latest ... Do you have sendmail listening on port 25...ie, ...
      (freebsd-isp)
    • Re: Clarification on IO Operations
      ... > How Processor recognizes different IO devices based on Port ... port numbers are on the bus address lines. ... ranges it knows of. ... level solutions to the resource assignment problem. ...
      (comp.os.linux.development.system)