Re: FW1 External Ruleset validation tools?

From: Steve Shah (sshah_at_planetoid.org)
Date: 09/11/03

  • Next message: Phil Cox: "Anyone use the "commercial" version of WebSleuth?"
    Date: Thu, 11 Sep 2003 07:32:25 -0700
    To: ravi pina <ravi@cow.org>
    
    

    > > I'm looking for a way to audit my firewall ruleset, in
    > > a very specific manner.

    Check Freshmeat.net. There is a tool there called pacgen that
    will generate arbitrary IP packets. You can use this to
    recreate your packet.

    First test that the packet is making it through your firewall.
    Once you have confirmation of that, enable whatever logging
    feature you want. Send the packet again, stop logging, and
    then sift through what you have. You'll have much less data to
    actually look through and ideally the ruleset being hit/missed
    will show up easily.

    -Steve

    -- 
    Steve Shah
    sshah@planetoid.org - http://www.planetoid.org/
    Beating code into submission, one OS at a time...
    ---------------------------------------------------------------------------
    FREE Trial!
    New for security consultants and in-house pros: FOUNDSTONE PROFESSIONAL 
    and PROFESSIONAL TL software. Fast, reliable vulnerability assessment 
    technology powered by the award-winning FoundScan engine. Try it free for  21 days at: http://www.securityfocus.com/sponsor/Foundstone_pen-test_030825
    ----------------------------------------------------------------------------
    

  • Next message: Phil Cox: "Anyone use the "commercial" version of WebSleuth?"

    Relevant Pages

    • Re: FW1 External Ruleset validation tools?
      ... We use Blade Software's Firewall Informer product - it does just what you ... >What is the easiest way to find out what rule line the supposed packet ... technology powered by the award-winning FoundScan engine. ...
      (Pen-Test)
    • FW1 External Ruleset validation tools?
      ... I'm looking for a way to audit my firewall ruleset, ... I've gotten reports of packets traversing our firewall ... What is the easiest way to find out what rule line the supposed packet ... Leif Sawyer ...
      (Pen-Test)
    • Re: WinRoute Pro
      ... the NAT table for I believe. ... packet logging shows some nice information but other times the ... when the connection is torn down from the client side ...
      (comp.security.firewalls)
    • RE: FW1 External Ruleset validation tools?
      ... FW1 External Ruleset validation tools? ... > What is the easiest way to find out what rule line the supposed packet ... in error, please contact us immediately at 816.421.6611, and delete the communication from any computer or network system. ... technology powered by the award-winning FoundScan engine. ...
      (Pen-Test)
    • RE: Help with Cisco
      ... clock summer-time EDT recurring ... >logging on the router and added the word log to the end of each line i ... >xxx.xxx.xxx.145, 1 packet ...
      (Security-Basics)