Re: [fw-wiz] Firewalls that generate new packets..
- From: "Marcus J. Ranum" <mjr@xxxxxxxxx>
- Date: Tue, 27 Nov 2007 19:28:29 -0500
jdgorin@xxxxxxxxxxxx wrote:
I also remember that early Checkpoint firewalls broke FTP connection if the PORT
command and the PORT arguments were sent in differents packets (back in those
old times, some FTP gateway did that kind of tricks).
That was deep but not smart inspection!
That was a side effect of the fact that they didn't do TCP reassembly,
packet defragmentation, or re-ordering. I always figured that they were
just doing a case-independent compare for "PORT " at the beginning
of the packet data.
Heck of a "state" engine, huh?
mjr.
_______________________________________________
firewall-wizards mailing list
firewall-wizards@xxxxxxxxxxxxxxxxxxxxx
https://listserv.icsalabs.com/mailman/listinfo/firewall-wizards
- References:
- Re: [fw-wiz] Firewalls that generate new packets..
- From: jdgorin
- Re: [fw-wiz] Firewalls that generate new packets..
- Prev by Date: Re: [fw-wiz] Firewalls that generate new packets..
- Next by Date: Re: [fw-wiz] Firewalls that generate new packets..
- Previous by thread: Re: [fw-wiz] Firewalls that generate new packets..
- Next by thread: [fw-wiz] Active-Active Single-context Failover on an ASA 5550
- Index(es):
Relevant Pages
|