Re: UDP packets are dropped by the PIX



On Fri, 23 Dec 2005, in the Usenet newsgroup comp.security.firewalls, in article
<doi16o$q6l$1@xxxxxxxxxxxxxxxxxxxxxxx>, Walter Roberson wrote:

>Within a "sanely configured firewall", one might want to
>tunnel VPN connections, such as to provide a higher security
>access to a financial system.

Not allowed on the company wire. The O/P was posting from the New York
City Public Schools network - I would hope that they also restrict
personal use of city property. Mentioned elsewhere, there are a few
systems in the employee break areas (which I now discover are actually
owned by the employee association), but those are not connected to the
company wire (they share a DSL connection paid for by the employee
association - that I knew).

>IPSec requires UDP for key negotiation (IKE), and if you are using NAT-T
>then it also needs UDP 4500.

I'm not at liberty to say, but connecting from my personal systems at
home to work doesn't show any UDP on a tcpdump. On the work system
which is on a company furnished line, the packets aren't even TCP, but
"another" protocol.

Old guy
.



Relevant Pages

  • Re: How to pass data From one Web Part to another?
    ... Please post questions to the newsgroup only. ... with connections. ... The second has additional employee details such as ... seniority and also the employee number. ...
    (microsoft.public.sharepoint.windowsservices)
  • Re: How to pass data From one Web Part to another?
    ... > Mike Walsh, Helsinki, Finland ... > with connections. ... The second has additional employee details such as ... > seniority and also the employee number. ...
    (microsoft.public.sharepoint.windowsservices)
  • Re: Joining data from 6 tables so I can produce a report.
    ... Add all the tables containing data you wish, and be sure the "Employee" ... Drag the connections between the Employee table and each of the others ... > much holiday people are entitled to, how much they have taken, and also ... and so the employees with no InLieu are not selected. ...
    (microsoft.public.access.queries)
  • Re: handover latency (use UDP or TCP)
    ... > between wired and WLAN connections as needed based on connectivity. ... > timings of last packet sent on first interface and first packet sent on ... i am thinking of using UDP as it ... I don't think I exactly understand the switchover part, ...
    (comp.os.linux.networking)
  • Re: bind() udp behavior 2.6.8.1
    ... i am aware that UDP is connectionless. ... However in terms of a firewall ... high port outbound connections destined for a DNS server will never be ... sort this out, we only have source ip and port. ...
    (Linux-Kernel)

Quantcast