Re: network policy checking



Sony C <raagamuffin@xxxxxxxxx> writes:

Hello fellow pen-testers,

I am looking for tools that perform network policy checking. Specifically, tools that allow the user to define a policy and then test the network elements to see if they adhere to this policy. As one might guess, this can be accomplished either via config file checking (passive) or actual network testing (active, via SNMP etc).
I am interested in both flavors, if they are available. These tools can be commercial or open-source/free/shareware.
While it is a broad requirement, this hypothetical tool will primarily be looking at routers, firewalls, etc.

Thank you in advance for sharing your thoughts.

Hi Sony,

Could you give some examples of specific routers and firewalls you're
looking to check, and what an example "network policy" issues you're
interested in? It might help focus down some of the recommendations.


------------------------------------------------------------------------
This list is sponsored by: Cenzic

Need to secure your web apps NOW?
Cenzic finds more, "real" vulnerabilities fast.
Click to try it, buy it or download a solution FREE today!

http://www.cenzic.com/downloads
------------------------------------------------------------------------



Relevant Pages

  • Re: Misconceptions
    ... > True routers route traffic much like the old railroad turntables ... Firewalls implement security policies or rules ... > handled by anti-virus programs, which should be on the ... > A NIDS is just that. ...
    (comp.security.firewalls)
  • Re: Misconceptions
    ... >> NAT can be implemented on many routers, but only on stub network (the ... usually a private/office network) routers. ... >> Routers are NOT firewalls. ... >> A NIDS is just that. ...
    (comp.security.firewalls)
  • Re: Do I really need firewall? A newbies question
    ... their own firewalls and you have the major ports blocked for the IPs ... you have assigned to your computers why would there be a reason to put ... router firewalls (on routers that I can afford lol) because it can lead ... I think this leads back to the age-old debate of which is better - ...
    (comp.security.firewalls)
  • Re: EIGRP or OSPF over WAN
    ... routing protocols EIGRP and OSPF so that 2 routers on different subnets ... LAN A - 172.16.116.0/22 and LAN B 172.16.120.0/22 and they ... the firewalls and these two networks are connected but the routers do ... best to use eBGP for going through firewalls and hoping across to subnets when interfaces of each end routers are on different subnets. ...
    (comp.dcom.sys.cisco)
  • Re: EIGRP or OSPF over WAN
    ... routing protocols EIGRP and OSPF so that 2 routers on different subnets ... LAN A - 172.16.116.0/22 and LAN B 172.16.120.0/22 and they ... the firewalls and these two networks are connected but the routers do ... doing so thats why they are running multiple Protocols. ...
    (comp.dcom.sys.cisco)