Re: stateful inspection

From: Keith W. McCammon (km@km.com)
Date: 12/19/01


From: "Keith W. McCammon" <km@km.com>
Date: Wed, 19 Dec 2001 09:26:01 -0500


> While that technology appears to be patented, Netgear has at least one
> product
> (RO-318 Security Router) that boasts about "stateful inspection".

I don't have any specifics, as I'd imagine that you'd have to pry those from
the clutches of Netgear. However, if they are advertising stateful
inspection, that's probably what you're getting. Checkpoint had patented
their stateful inspection scheme, but there are any number of firewalls out
there that keep session state. It's not groundbreaking technology. Just
about any worthwhile commercial firewall keeps state, as do most free
firewalls for use on *BSD or Linux.

All that stateful inspection entails is the creation of a memory-resident
table, and as SYN packets arrive, you add new connections to that table.
Anything else that arrives with SYN/ACK, ACK, FIN, or RST must match an
existing connection in the state table to be passed. Checkpoint does it one
way (which, up until 4.1 SP2, was still pretty crappy because you could send
an ACK to start a session and it would be added to the state table), but any
vendor could implement this effectively.



Relevant Pages

  • Re: For Sale IPAQ with dcf-660w Air card
    ... suggest turning off all firewalls and assign a static IP (including gateway ... and DNS) to the iPAQ network adapter. ... > what happened to Go and Stop and On and Off technology? ... > to my wireless router and give me access to mobile browsing on my pda but ...
    (microsoft.public.pocketpc)
  • Re: OWA problem
    ... Maybe look into the "allowed" http commands in the Netgear. ... I don't know anything about the Netgear firewalls, ... are able to get to it, it would not even use WebDav for that. ... >> Matthew Tisdel ...
    (microsoft.public.exchange.admin)
  • Firewalls and Security
    ... I read the thread Firewalls about four or five posts deep and had to ... Firewalls refers to a specific technology, ... You would not refer to wireless technology when talking about cordless ... cordless phones, not wireless devices. ...
    (alt.computer.security)
  • Re: Firewall
    ... PPTP, myself. ... > Perhaps Netgear router have some basic packet filtering and NAT ... > but we can possibly expect stateful inspection, ... > analysis and logging from a firewall. ...
    (microsoft.public.security)
  • Re: Direct Advertiser
    ... I like Netgear too for home firewalls, since you can telnet in and add like ... 24 to 36 filtering rules like a real firewall... ... which rather increases the price. ...
    (microsoft.public.security)