[fw-wiz] PC Firewall Evaluations



Greetings to all,

This is the first time I've posted here, so be gentle with me if my inquiry
is foolish. I have need to compile and maintain an extended list of PC
Firewalls both commercial and public and rank them. I don't really have the
time to get deep into to this, so I thought I'd ask around on this list.

Particularly vulnerabilities, performance, reliability, manageability, user
interface, etc. Basically a composite metric of some sort. Ideally, this
would be simply the list of ICSA certified PC Firewall products, however, it
is quite short and there are many products in the market being used by
consumers. Some, no doubt, are better than others. I've searched around and
have not found anything that is clearly a standards based ranking or
certification short of ICSA certification and again that is a short list.

For example: HYPERLINK
"http://www.icsalabs.com/icsa/main.php?pid=ghffguj657"http://www.icsalabs.co
m/icsa/main.php?pid=ghffguj657 is a great certification program, trouble is,
like all quality programs, it costs money to administrate them and many
small PC Firewall vendors can't or won't pay the fees. For obvious reasons,
some vendors may choose not to have their ICSA evaluations made public. It
would be great if they all could or would but it is what it is.

Another example: HYPERLINK
"http://personal-firewall-software-review.toptenreviews.com/"http://personal
-firewall-software-review.toptenreviews.com/ and HYPERLINK
"http://www.firewallguide.com/software.htm"http://www.firewallguide.com/soft
ware.htm are nice lists, however, they leave out vulnerabilities and
performance rankings and those are critical metrics. In other words, they
are non-technical and don't specifiy test & ranking methods.

Excepting the ICSA list, most look like marketing fluff to me. Please set me
straight if I'm missing anything here.

Does anyone know of a comprehensive list of non-ICSA certified PC Firewalls
that have been recently tested using popular exploit vulnerability and
intrusion detection tools such as Metasploit and Snort/Air Snort?

Best,

Vin







--
No virus found in this outgoing message.
Checked by AVG Free Edition.
Version: 7.1.409 / Virus Database: 268.14.0/525 - Release Date: 11/9/2006

_______________________________________________
firewall-wizards mailing list
firewall-wizards@xxxxxxxxxxxxxxxxxxxxx
https://listserv.icsalabs.com/mailman/listinfo/firewall-wizards


Relevant Pages

  • Windows 2000 server issue
    ... accurately parse the lists of vulnerable machines produced by the scan ... of addresses directly on the script. ... Summer's Hottest Certification Just Got HOTTER! ... you can save 33% off of the TICSA certification ...
    (NT-Bugtraq)
  • SUMMARY: Stop the idiotic questions and useless summaries, please [plus additional resources]
    ... because it includes a substantial number of resources that I find useful ... I recommend avoiding all mailing lists hosted by either Topica or Yahoo ... firewalls: firewalls-subscribe@lists.securityfocus.com ... There are NUMEROUS books on Sun systems admin, ...
    (SunManagers)
  • Re: So long and thanks a bunch!
    ... pen-test still belongs to you, I'm just doing extended guest moderator ... I wanted to send a quick note to those of you on these two lists who ... Pen-Test was the first list I created after I founded SecurityFocus ... Information Assurance Certification Review Board ...
    (Pen-Test)
  • Re: "Messenger Service" Pop Up
    ... >> service is wide open to Internet Attackers. ... >> different pop up lists a different web site to go to to ... > I don't recommend stopping the messenger service. ... Right again, except for the firewalls! ...
    (microsoft.public.security)
  • Re: What is a "Predicate delegate"
    ... Show me your certification without works, ... use of Delegates which is used with various Generic Lists, ... The Predicate delegate is a Generic method which takes an object of type ...
    (microsoft.public.dotnet.languages.csharp)