Re: Netscreen doesn't block established connections

From: Leythos (void@nowhere.com)
Date: 12/19/02


From: Leythos <void@nowhere.com>
Date: Thu, 19 Dec 2002 03:58:39 GMT

In article <slrnb01pce.nag.oskov@ux10.cso.uiuc.edu>,
oskov@students.uiuc.edu says...
> Hey guys,
> I am testing a Netscreen 5XT firewall and it puzzles me with this.
> I start with fresh allow all setup. I connect to host in the inside
> network with ssh. I put the following rule in the firewall
> set policy incoming any-outside our-network ssh deny
> where any-outside and our-network are the network definitions.
> All new connections are blocked fine, but this one that was established
> never gets blocked. I can still use it until I logout.
> Anyone seen this behavior and knows how to prevent it?

I hate to see that - I wanted our Corporate offices to standardize on
Watchguard and they went with Netscreen. WG stops all connections when
you update/create a rule for it - even in session ones.

-- 
--
Leythos999@columbus.rr.com
(Remove 999 to reply to me)


Relevant Pages

  • Netscreen doesnt block established connections
    ... I am testing a Netscreen 5XT firewall and it puzzles me with this. ... I connect to host in the inside ... set policy incoming any-outside our-network ssh deny ... where any-outside and our-network are the network definitions. ...
    (comp.security.firewalls)
  • Re: Netscreen doesnt block established connections
    ... new rules won't zap established connections. ... > I am testing a Netscreen 5XT firewall and it puzzles me with this. ... > set policy incoming any-outside our-network ssh deny ... > where any-outside and our-network are the network definitions. ...
    (comp.security.firewalls)
  • Re: What is the Pattern here ?
    ... These are all Dialup Connections that I had no connection with at the time. ... It's obviously an enormous security hole, ... > and a real firewall box. ...
    (comp.security.firewalls)
  • Re: Black Ice confesses faulty program!!!
    ... > outgoing connections or traffic except in cases where these connections ... > "dangerous/suspicious" traffic by the BlackICE program. ... > get into your machine then even a PC *without* a firewall is completely ... If you don't think "Spyware" is a problem for computer ...
    (comp.security.firewalls)
  • Re: Port 135
    ... The patch doesn't disable DCOM / RPC, so connections can still be made. ... That's why you need a firewall. ... the patch is not the thing to control ... control over your TCP/IP ports and services, ...
    (microsoft.public.security)

Loading