Re: Access Control filtering of OS's?

From: Mailman (mailman_at_anonymous.org)
Date: 10/21/04

  • Next message: Steve: "Re: Norton Firewall"
    Date: Thu, 21 Oct 2004 17:41:54 +0200
    
    

    TF wrote:

    > Hi,
    >
    > Does anybody know of a decent hardware firewall by one of the main
    > vendors that can filter access by operating system and handle 600-1000
    > hosts. I'm not sure if this is a common feature on firewalls but any
    > advice would be appreciated.
    >
    > Rgds,
    >
    > TF

    Not hardware (though it is used in a few appliances), and not "main
    vendor" (whatever that may mean): OpenBSD has OS fingerprinting as part of
    the firewall - you can create access rules based on the OS you are talking
    to. It works reasonably well, but it is rarely needed. Are you quite sure
    you really mean what you asked?

    I would also suggest you qualify the "600-1000 hosts": that may mean little
    traffic (you only have normal office usage, no Internet) or very heavy (a
    college campus, serious corporate database). In any case, if you run 1000
    machines unsegmented you have larger things to worry about than just OS
    identification.

    -- 
    Mailman
    ----== Posted via Newsfeeds.Com - Unlimited-Uncensored-Secure Usenet News==----
    http://www.newsfeeds.com The #1 Newsgroup Service in the World! >100,000 Newsgroups
    ---= East/West-Coast Server Farms - Total Privacy via Encryption =---
    

  • Next message: Steve: "Re: Norton Firewall"

    Relevant Pages

    • RE: [fw-wiz] CERT vulnerability note VU# 539363
      ... so vendors shoot for the former. ... > In my opinion if a stateful firewall claims it can filter at rate X ... > a stateless packet filter is going to be vulnerable to these sort ...
      (Firewall-Wizards)
    • RE: [fw-wiz] so much for "deny all"
      ... >> vendors like Juniper Networks, Check Point and Fortinet employ a ... > This is very good publicity for firewall vendors not in the list who ... (if anyone in this politically correct time still indulges in multi-martini ... the company at which I did my first firewall install replaced the ...
      (Firewall-Wizards)
    • Re: How to choose an IDS/FW MSS provider
      ... > plenty of other competent vendors out there are doing R&D. ... > Firewall vendors are trying to catch up on the Layer 7 analysis. ... With the obvious success of IPS technologies at the perimeter, ...
      (Focus-IDS)
    • [fw-wiz] Firewall Sizing?
      ... How do you go about sizing a firewall? ... Anyway, as with most vendors there's a number of models and a number of specs that vary as you move up the range - throughput, max sessions, recommended users etc. ... What puts the most load on a modern firewall such as a Sidewinder, is it sheer throughput, is it keeping track of X sessions to/from Y clients and so on? ...
      (Firewall-Wizards)
    • Re: Tiny Vs Norton vs ZA
      ... >firewall if I had the urge. ... be-all of security on the Internet. ... >multiple vendors. ... >context of most home/personal users. ...
      (comp.security.firewalls)

  • Quantcast