Re: [fw-wiz] Firewalls that generate new packets..



on 2007-11-28 08:21 Darden, Patrick S. said the following:
No offense, but both of you are wrong.
Properly configured, a simple firewall
CAN prevent most DOS attacks.

I am really confused here. I've read BCP38 (which your paper obliquely
references). I guess you mean: if I have a firewall, I can prevent DOS
attacks from *originating from my network*, as opposed to what I see as
the more popular interpretation of "help you against DOS attacks" to
mean "mitigate the damage of DOS attacks inbound on my network".

Check out this SANS bulletin on
"Defeating DDOS". Yes, that is my
name in the credits. Special task
force back in 2000. Sigh, and still
people don't know that you can use
a simple firewall to defeat most
DOS attacks... as long as you are
protecting the world from YOUR
network.

I can do all the source filtering I want, but if I'm receiving 500 Mpps
of DDOS, my firewall's gonna keel over and die. (Maybe I'm off by 10 dB
or so...)

Any plan of action that depends on the compliance of vendors and
everyone else on the Internet is...well, I'd love the IOS command that
would allow me to configure my neighbor's router.

--p

//jbaltz
--
jerry b. altzman jbaltz@xxxxxxxxxxx www.jbaltz.com
thank you for contributing to the heat death of the universe.
_______________________________________________
firewall-wizards mailing list
firewall-wizards@xxxxxxxxxxxxxxxxxxxxx
https://listserv.icsalabs.com/mailman/listinfo/firewall-wizards



Relevant Pages

  • Re: Sessions Resource Exhaustion
    ... i could exhaust all states in my SME firewall. ... that this firewall is kept in real network. ... some kind of random drop or session rate policing once session flood ... can i say that these devices are vulnerable to simple DoS attacks? ...
    (Focus-IDS)
  • Re: Please enable firewalls by default on Linux distributions
    ... A seat belt is no use if you are doing 150 mph, having a firewall does not ... > Most of Linux comes with dozens of resource-limits turned on. ... > To keep the O/S from being too easily compromised. ... >> of technology is on the internet to get DOS attacks. ...
    (comp.os.linux.security)
  • RE: win2k firewall
    ... > A good firewall gives you more functionality than ... I'd like to hear what DoS attacks you're ... there that target the Win2K IP stack? ... > Firewalls aren't just to protect you against the ...
    (Security-Basics)
  • Re: Firewall and Win2k
    ... Agnitum Outpost does a great job blocking DoS attacks. ... >> I'm using Tiny Firewall, ... >of them protect against DoS. ...
    (microsoft.public.win2000.security)
  • Re: [fw-wiz] Firewalls that generate new packets..
    ... Properly configured, a simple firewall ... CAN prevent most DOS attacks. ... "Defeating DDOS". ...
    (Firewall-Wizards)