[fw-wiz] FW and TCP Sessions

From: Manoj Kumar Neelapareddy (manojkreddyutl_at_yahoo.com)
Date: 06/01/04

  • Next message: Paul D. Robertson: "Re: [fw-wiz] Vulnerability Response (was: BGP TCP RST Attacks)"
    To: firewall-wizards@honor.icsalabs.com
    Date: Tue, 1 Jun 2004 04:49:23 -0700 (PDT)
    
    

    Hi,

    if a FW is said to be a stateful firewall, then will
    it allow a TCP packet to pass through it(outbound), if
    i haven't sent a TCP SYN to initiate a TCP Session
    before sending this TCP packet?

    I heard that Statefull firewall won't allow any TCP
    packets, other than TCP SYNs to pass through it, if
    there is no session corresponding a TCP packet is
    maintained in FW's session table.

    and FW will create a new session only when it detects
    a TCP SYN.

    is this correct?

    comments plz.

    thank u
    Manoj

            
                    
    __________________________________
    Do you Yahoo!?
    Friends. Fun. Try the all-new Yahoo! Messenger.
    http://messenger.yahoo.com/
    _______________________________________________
    firewall-wizards mailing list
    firewall-wizards@honor.icsalabs.com
    http://honor.icsalabs.com/mailman/listinfo/firewall-wizards


  • Next message: Paul D. Robertson: "Re: [fw-wiz] Vulnerability Response (was: BGP TCP RST Attacks)"

    Relevant Pages

    • Re: [fw-wiz] FW and TCP Sessions
      ... > if a FW is said to be a stateful firewall, ... > i haven't sent a TCP SYN to initiate a TCP Session ... > before sending this TCP packet? ...
      (Firewall-Wizards)
    • Re: [fw-wiz] FW and TCP Sessions
      ... >if a FW is said to be a stateful firewall, ... >i haven't sent a TCP SYN to initiate a TCP Session ... >before sending this TCP packet? ...
      (Firewall-Wizards)
    • Re: TCP socket - how to get rid?
      ... > TCP packet that can be sent to the signaling a close. ... Yes, theoretically it is possible to sent to peer a packet imitating normal TCP CLOSE, ... Who will set the state of TCP socket in the kernel to FIN-WAIT-1? ...
      (comp.os.linux.networking)
    • Re: ipfw: reset tcp
      ... E>>> When a rule 'reset tcp' matches, a kernel generates new TCP packet. ... E>> ipfw2 uses an mbuf flag to bypass the firewall - I am not sure if i ...
      (freebsd-net)
    • Re: Accessing raw TCP packet payload data
      ... As has already been mentioned you can use raw sockets etc to access this ... a TCP packet, using .NET. ... fit inside a single TCP packet. ... Chris Crowther ...
      (microsoft.public.dotnet.general)