RE: [Full-Disclosure] PIX vs CheckPoint

From: Otero, Hernan (EDS) (HOtero_at_lanchile.cl)
Date: 06/30/04

  • Next message: Jaroslaw Sajko: "Re: [Full-Disclosure] PIX vs CheckPoint"
    To: full-disclosure@lists.netsys.com
    Date: Wed, 30 Jun 2004 07:58:58 -0400
    
    

    I think you do, because at least a nat 0 it´s needed to get traffic passing
    through the pix.

    -H

    -----Original Message-----
    From: Cyril Guibourg [mailto:plonk-o-matic@teaser.fr]
    Sent: Miércoles, 30 de Junio de 2004 4:30
    To: Laurent LEVIER
    Cc: Darkslaker; full-disclosure@lists.netsys.com
    Subject: Re: [Full-Disclosure] PIX vs CheckPoint

    Laurent LEVIER <llevier@argosnet.com> writes:

    Hi L2,

    > At the NAT level, you have to know Pix is a NATing box and everything
    > it does is based on NAT.

    AFAIK, a PIX can operate without NAT. Did I miss something ?

    _______________________________________________
    Full-Disclosure - We believe in it.
    Charter: http://lists.netsys.com/full-disclosure-charter.html

    _______________________________________________
    Full-Disclosure - We believe in it.
    Charter: http://lists.netsys.com/full-disclosure-charter.html


  • Next message: Jaroslaw Sajko: "Re: [Full-Disclosure] PIX vs CheckPoint"

    Relevant Pages

    • RE: [Full-Disclosure] PIX vs CheckPoint
      ... There are better tools to admin rules, like fwbuilder for pix... ... Subject: [Full-Disclosure] PIX vs CheckPoint ... Charter: http://lists.netsys.com/full-disclosure-charter.html ...
      (Full-Disclosure)
    • Re: [Full-Disclosure] PIX vs CheckPoint
      ... You must have some static's in place then, which is a static 'NAT' ... Cyril Guibourg wrote: ... Full-Disclosure - We believe in it. ... Charter: http://lists.netsys.com/full-disclosure-charter.html ...
      (Full-Disclosure)
    • Re: [Full-Disclosure] PIX vs CheckPoint
      ... AFAIK, a PIX can operate without NAT. ... Full-Disclosure - We believe in it. ...
      (Full-Disclosure)
    • Re: PIX DOS (config problem) - Similar to NetScreen ScreenOS...
      ... as manually configuring access to the NAT pool. ... I always prefer explicit filters when configuring routers, ... PIX hard enough that it matters, they probably shouldn't be using that PIX ... Maybe Cisco should change the PIX ...
      (Bugtraq)
    • Re: PIX 506e VPN Tunnel - Can This Be Done
      ... on my remote PIX I have been asked not to enable the NAT ... static tcp interface PORT INTERNALIP PORT netmask 255.255.255.255 ...
      (comp.dcom.sys.cisco)