Re: [fw-wiz] Firewalls that generate new packets..
- From: "Patrick M. Hausen" <hausen@xxxxxxxx>
- Date: Sat, 24 Nov 2007 00:08:35 +0100
Hello,
On Fri, Nov 23, 2007 at 05:07:23PM -0500, Paul D. Robertson wrote:
On Mon, 19 Nov 2007, Paul Melson wrote:
and has a miniscule share of the total firewall market. Of course, Cisco,
Check Point, and most of their competitors have proxies. Proxy firewalls
are dead. Long live proxy firewalls.
But if my experience with Internet-enabled software vendors is anywhere
near common, nobody's enablign the proxies.
Absolutely correct. Because at least for one of these vendors
the proxies are riddled with bugs, i.e. protocol violations or,
to the customer, arbitrary restrictions, and, additionally,
performance plummets faster than <insert favorite comparison>.
These proxies are (IMHO) just a check item for people who buy
products based on check lists.
You need to design a firewall for use of proxies as your main
line of defense from the ground up. Fortunately current CPU
speeds and RAM capacities show the "stateful packet filters
are faster" argument not to be true anymore. At least not
if implemented on general purpose hardware.
The product with the "miniscule share of the total firewall market"
can easily support Gigabit speeds.
Of course I'm biased, but I happen to have a customer with
about 14.000 seats running both Checkpoint and Secure Computing.
You should talk to their IT staff.
They introduced Checkpoint firewalls when your "high end" ALG
was Gauntlet on a Sun E450. A current Sidewinder runs circles
around these boxes. With much more thorough protocol inspection
than Gauntlet ever had. Sorry, ^inspection^enforcement. ;-)
Kind regards,
Patrick M. Hausen
Leiter Netzwerke und Sicherheit
--
punkt.de GmbH * Vorholzstr. 25 * 76137 Karlsruhe
Tel. 0721 9109 0 * Fax 0721 9109 100
info@xxxxxxxx http://www.punkt.de
Gf: Jürgen Egeling AG Mannheim 108285
_______________________________________________
firewall-wizards mailing list
firewall-wizards@xxxxxxxxxxxxxxxxxxxxx
https://listserv.icsalabs.com/mailman/listinfo/firewall-wizards
- Follow-Ups:
- Re: [fw-wiz] Firewalls that generate new packets..
- From: Dave Piscitello
- Re: [fw-wiz] Firewalls that generate new packets..
- References:
- Re: [fw-wiz] Firewalls that generate new packets..
- From: Paul Melson
- Re: [fw-wiz] Firewalls that generate new packets..
- From: Paul D. Robertson
- Re: [fw-wiz] Firewalls that generate new packets..
- Prev by Date: [fw-wiz] How to find hidden host within LAN
- Next by Date: [fw-wiz] Cisco firewall appliance choice
- Previous by thread: Re: [fw-wiz] Firewalls that generate new packets..
- Next by thread: Re: [fw-wiz] Firewalls that generate new packets..
- Index(es):
Relevant Pages
|