[fw-wiz] Help



Can I ask some of you who live behind commercial firewalls to do the following DNS dig for a small study I would like to conduct?

dig hk ns +bufsize=4096 @203.119.2.18 > <file>

If you could tell me the OS you used to dig, the firewall between your resolver and the name server and if you know, the firewall SW version, you'd really make my day. BTW, if you don't get an answer, that is a very useful data point.

I am trying to gather some anecdotal evidence regarding how firewalls deal with EDNS0 responses (esp. DNS messages > 512) and AAAA records.

I have results for
Netscreen (ScreenOS V5.30r3, 4.0.3r4.0)
Sonicwall (SonicOS Standard 3.1.0.7-77s)
Cisco PIX version 7.2.1
Cisco C2600 IOS 12.2(37)
Watchguard FBX1000 (Fireware v8.2)

I could really use some data from current and previous versions of Checkpoint, Symantec, Sidewinder, Fortinet to help fill out the "market share tested" pie chart.


begin:vcard
fn:David Piscitello
n:Piscitello;David
adr;dom:;;3 Myrtle Bank Lane;Hilton Head;SC;29926
email;internet:dave@xxxxxxxxxxx
x-mozilla-html:FALSE
url:http://hhi.corecom.com/weblogindex.htm
version:2.1
end:vcard

Attachment: smime.p7s
Description: S/MIME Cryptographic Signature

_______________________________________________
firewall-wizards mailing list
firewall-wizards@xxxxxxxxxxxxxxxxxxxxx
https://listserv.icsalabs.com/mailman/listinfo/firewall-wizards


Relevant Pages

  • RE: Security for new small company
    ... But if you want to create a DMZ with the mail server and website you could buy a Cisco PIX 515R that has three or more ethernet interfaces to do it. ... >soon and i'm thinking about firewalls and ... >Ideally we would like a hardware soloution for the ... >hosting company. ...
    (Security-Basics)
  • Re: Cisco PIX 515 Firewall
    ... Subject: Cisco PIX 515 Firewall ... I have had the pleasure / misfortune to have used the Pix 515 Firewalls ... As for advice - take some quality time to read the manual and become ... based on addresses/ports but actually look at packet content like a proxy ...
    (Security-Basics)
  • Re: [fw-wiz] Disecting the Cisco PIX
    ... Cisco PIX is technically at the low end of packet filtering routers ... built this way. ... According to a market analysis, there are more such boxes running ... firewalls. ...
    (Firewall-Wizards)
  • Re: Best Firewall
    ... >>into a Cisco PIX, SonicWALL, etc... ... > I understand the arguments against software firewalls and pro hardware ... > Until there are sub $100 dollar hardware firewalls, ...
    (comp.security.firewalls)
  • Re: Best Firewall
    ... >into a Cisco PIX, SonicWALL, etc... ... I understand the arguments against software firewalls and pro hardware ... Cisco, Sonicwall, and others would be developing low cost hardware ... Until there are sub $100 dollar hardware firewalls, ...
    (comp.security.firewalls)