Re: NAT vs. True Firewalls

From: Damir Ozega (damir66_hr@yah2o.com)
Date: 01/31/02


From: "Damir Ozega" <damir66_hr@yah2o.com>
Date: Wed, 30 Jan 2002 19:36:09 -0500


> A firewall, on the other hand, has the capability to decode
> application-layer data, perform pattern-matching, stream reassembly, as
well
> as other safeguards that would have stopped me from sending bad code.

Which feature allows pattern matching on Linux/BSD firewall's (like
ipchains, iptabless/ipf)

> Additionally, it would have seen that Joe User wasn't actually sending a
web
> connect string to port 80, and it would have dropepd his connection
attempt
> to my server.

Again - could you pint out where to look for those capabilities.

Thanks.