Re: [fw-wiz] Evolution of Firewalls

From: Marcus J. Ranum (mjr_at_ranum.com)
Date: 03/12/04

  • Next message: Kyle King: "[fw-wiz] Cisco PiX 501 running 6.2 - Defying me for no reason"
    To: Chunduru Rama Krishna Prasad <rkp@intotoinc.com>, <skpoo@pacific.net.sg>, <firewall-wizards@honor.icsalabs.com>
    Date: Fri, 12 Mar 2004 00:04:16 -0500
    
    

    > Application proxy firewalls run based on the applications. Example new application comes in market again you have to write new application proxy .

    By the way, many of us "old school" proxy firewall guys think this is one
    of the main value propositions for a proxy. It means that a set of security
    eyes are focused (however briefly) on the protocol that is being gatewayed.
    This often pays huge dividends because it seems that most app-protocols
    are braindamaged. I remember when Dave Dalva at TIS did some assessment
    (as part of our HTTP proxy design) on the NCSA "Mosaic" web browser
    and found some absolute howlers of security holes (coded by some genius
    named "Andreeson"...) -- this was stuff that everyone else had just rushed
    into production with their screening and "stateful multi-blahblah packet blah"
    firewalls. When I first started looking at FTP in '89/90 to build my first FTP
    proxy, I realized FTP bounce attacks were possible, etc, etc.

    Another BIG value of proxies is that they can implement only subsets
    of a protocol. Whereas you actually had to try to build a reduced
    instruction set FTPD to make a secure(ish) FTP server you could stick
    a proxy in the way and only allow RETR and PORT with the destination
    equal to the client address. Or you could implement a bare minimum
    of an SMTP protocol, as another example. It saves you having to
    understand all the security properties of the entire app-protocol stack -
    which is sometimes impossible with today's braindamaged protocols.
    (e.g.: Anyone understand all of SMB?)

    >3. Performance.

    This is largely an artifact of popular implementations rather than
    a "must be" - I saw some very cool demoes of one of the Seaway
    gig-networking app card the other day. It does TCP termination
    and what we'd call "transparent proxying" (with IP scrubbing
    thrown in) at 4 gigs/sec. That's with the card acting as both
    sides of a TCP stack, just like ye olde proxy firewall used to do.
    You could write a proxy atop that puppy to process the app-layer
    session commands and make a "stateful blah multi-level poo poo
    blah blah" firewall look like a paralytic centipede in comparison.

    mjr.

    _______________________________________________
    firewall-wizards mailing list
    firewall-wizards@honor.icsalabs.com
    http://honor.icsalabs.com/mailman/listinfo/firewall-wizards


  • Next message: Kyle King: "[fw-wiz] Cisco PiX 501 running 6.2 - Defying me for no reason"

    Relevant Pages

    • Re: [fw-wiz] dirty packet tricks?
      ... solve via promiscuously sucking up packets. ... restriction that your 'sideways' proxy box is it will have to be on a hub ... The firewall will have to suppress all ICMP errors to the internal network ...
      (Firewall-Wizards)
    • Re: [fw-wiz] httport 3snf
      ... >> wouldn't have gotten SSH out of my firewall. ... > Postfix SMTP server with a wildcard MX that handed the mail that wasn't ... > destined to me off to the downstream MS stuff, and an HTTP proxy server ... All it needs is a written policx "Internet access is ...
      (Firewall-Wizards)
    • Re: Kids bypassing firewall via web proxy sites
      ... We use a Sonicwall firewall, 3060, I subscribe to content fltering, ... I checked "Access to HTTP Proxy Servers" But I am still able to get to ... CyBlock, which does network proxy and filtering ...
      (comp.security.firewalls)
    • Re: NAT is not a mechanism for securing a network.. but.. HELP!
      ... tell you a NAT router is a firewall. ... > There is this one hot chick at a major American news network, ... >proxy, and come to a chat room where her and I have been chatting, she has ... >admins at the station she works for. ...
      (comp.security.firewalls)
    • Re: Tool to find hidden web proxy server
      ... No reason the proxy has to be INSIDE your firewall. ... Cell Phones to just bypass your firewall completely. ... On Thu, 2 Sep 2004, vinay mangal wrote: ... policy for Internet access says it is through IP ...
      (Pen-Test)

  • Quantcast