Re: Firewall Comparisons

From: Bryan S. Sampsel (bsampsel_at_libertyactivist.org)
Date: 07/07/03

  • Next message: Brad Bemis: "RE: Ten least secure programs"
    Date: Mon, 07 Jul 2003 10:30:52 -0600
    To: security-basics@securityfocus.com
    
    

    (snipped for brevity)

    Keith A. Glass wrote:
    > -----Original Message-----
    <snip>
    >
    >
    > I admit to a predjudice towards firmware-based firewalls, only because the
    > underlying OS's of an OS-based firewall may or may not be properly hardened.

    <snip>

    Likewise, some idiot can (and I've seen this happen) create a wide-open
    ACL on a PIX firewall. Doesn't make the box the problem. Means it was
    misconfigured and not hardened enough.

    >
    > When examining closely on of the two Checkpoints, I noticed the S78sendmail
    > script
    > was still in /etc/rc2.d. Since Sendmail is verboten on all but two
    > specially
    > designated servers in our net, I examined the box more closely, and found it
    > to
    > be a generic Solaris 8 Core package with no hardening whatsoever, not even
    > services
    > commented out in /etc/inetd.conf. . .
    >
    > That CAN'T happen on a firmware-based box, hence my predjudice for them over
    > OS-based
    > boxes

    <snip>

    Granted. This cannot happen when a feature does not exist on a device.
      It also means that the product being critiqued is a more flexible
    product with a wider range of potential services to offer. And yes,
    that can be a two edged sword.

    Like the PIX I mentioned above, if misconfigured, it is less than secure.

    With both, misconfigurations are the kiss of death. Kinda reminds me of
    the old GIGO (garbage in - garbage out) acronym. If the guy building
    the rules or specifying which services are available, screws up, your
    whole box can be compromised...firmware or not.

    IMHO,

    bryan

    ---------------------------------------------------------------------------
    Evaluating SSL VPNs' Consider NEOTERIS, chosen as leader by top analysts!
    The Gartner Group just put Neoteris in the top of its Magic Quadrant,
    while InStat has confirmed Neoteris as the leader in marketshare.
         
    Find out why, and see how you can get plug-n-play secure remote access in
    about an hour, with no client, server changes, or ongoing maintenance.
              
    Visit us at: http://www.neoteris.com/promos/sf-6-9.htm
    ----------------------------------------------------------------------------


  • Next message: Brad Bemis: "RE: Ten least secure programs"

    Relevant Pages

    • Re: XP Less Secure than 98 for Sharing Files
      ... Ever tried chasing up settings ... > that and/or your firewall supports it) or running with no firewall. ... If you have TCP/IP loaded at all, regardless of NetBEUI, and have Internet ...
      (microsoft.public.windowsxp.security_admin)
    • Re: some reality about iptables, please
      ... He also links it to adaptive firewall rules ... harsh critical review by security professionals, ... BTW, my previous post should have indicated PRE-up and POST-down clauses ...
      (Debian-User)
    • RE: Wireless access
      ... I think the DMZ interface of a firewall is probably ... on the dmz interface, and in a perfect world, an IDS sensor listening. ... to facilitate one-on-one interaction with one of our expert instructors. ...
      (Security-Basics)
    • Re: Router/Firewall Recommendation
      ... he wants to know his options with linux firewall. ... just by reading this threads I learn what my options are ...
      (RedHat)