Re: Bridging Firewalls
From: Eirik Seim (eirik@mi.uib.no)Date: 05/29/02
- Next message: Jeff Cochran: "Re: which firewall"
- Previous message: Bob Fryer: "Re: Smoothwall 0.9.9 and Zyxel 642R ADSL PortForwad?"
- Messages sorted by: [ date ] [ thread ] [ subject ] [ author ] [ attachment ]
From: eirik@mi.uib.no (Eirik Seim) Date: 29 May 2002 11:42:44 GMT
On Wed, 29 May 2002 10:03:09 +0000, Dave Pimlott wrote:
> Bob Yeaw wrote:
> >
> > I have been reading alot about bridging firewalls using OpenBSD and PF
> > or IPF and it seems like a great idea. Does anyone know of any
> > gotchas or problems with this approach? What attacks are possible on
> > a Packet filter with no IP address?
> >
>
> the only vulnerabilities I can think of are Ethernet attacks rather than
> TCP/IP attacks, e.g. MAC broadcast storms (which are hard to do
> remotely...)
> In terms of gotchas I can't think of any! In situations like this I
> "suck it and see".
Agreed. I think tunnelling and masquerading as legitimate traffic, i.e.
not attacking the firewall itself, as it can be truly invisible unless
on the same LAN (not touching the TTL), is a much greater threat than
the firewall itself beeing compromised.
One possible scenario could perhaps be if the filtering software can be
crashed. The filtering bridge is nothing but a bridge until the filtering
is applied, so I would assume it would be wide open if the filtering
software suddenly dies for some reason. Beeing more or less integrated into
the kernel, I would be very interested to see if anyone has experience
from this. Is it possibly for pf, ipf or even ipfw to crash in some
spectacular new way, leaving the networks unprotected?
Posting (and FUT) to comp.security.firewalls also, as I assume Berk and
possibly others there have opinions about this :)
- Eirik
-- New and exciting signature!
- Next message: Jeff Cochran: "Re: which firewall"
- Previous message: Bob Fryer: "Re: Smoothwall 0.9.9 and Zyxel 642R ADSL PortForwad?"
- Messages sorted by: [ date ] [ thread ] [ subject ] [ author ] [ attachment ]
Relevant Pages
|
|