Re: how to audit/test if firewall keep track of state/session

From: CZ (CZ@no99spam.com)
Date: 03/26/03


From: "CZ" <CZ@no99spam.com>
Date: Wed, 26 Mar 2003 21:08:56 GMT


> I am evaluating a couple firewalls for my organization now. Lot of
firewalls claim they can maintain session/state information.
Can someone suggest some way to test how "stateful" a firewall is.

Don/Jeff:

Run nmapnt against it. http://www.eeye.com/html/Research/Tools/nmapNT.html
Some of the simple things that stateful should catch, that stateless should
not:
Source address spoofing.
ACK packet not part of a connection



Relevant Pages

  • Re: Stateful Inspection
    ... >> A stateful firewall can inspect the contents of the packets as well. ... > VisNetic Firewall falls into a class of firewalls called Stateful ... Stateful inspection firewalls overcome the ...
    (comp.security.firewalls)
  • Re: Stateful Inspection
    ... >> A stateful firewall can inspect the contents of the packets as well. ... > VisNetic Firewall falls into a class of firewalls called Stateful ... Stateful inspection firewalls overcome the ...
    (comp.security.firewalls)
  • Re: pppoe, cant ping tun0, ipfnat ftp proxy "doesnt work"
    ... > But I noticed that, although you use ipnat(8), nat is also enabled in your ... especially on the way packets flow through the ... firewalls, so I dropped back and enabled in in ppp. ... Combining stateful rules and dummynet in ipfwwas interesting. ...
    (freebsd-net)
  • Re: Firewalls purchase research
    ... Hardware firewalls are nothing but a motherboard, ... > I will take my ISA server running layer 7 inspection on a Proliant dual ... The stuff most basic "stateful" ...
    (microsoft.public.security)
  • Re: Stateful Inspection
    ... > A stateful firewall can inspect the contents of the packets as well. ... Stateful Packet Inspection ... VisNetic Firewall falls into a class of firewalls called Stateful ... Stateful inspection firewalls overcome the ...
    (comp.security.firewalls)