Great Circle Associates Firewalls
(October 1992)
 

Indexed By Date: [Previous] [Next] Indexed By Thread: [Previous] [Next]

Subject: Re: Quality of Wellfleet IP filtering
From: Mark Moraes <deshaw!moraes @ cmcl2 . NYU . EDU>
Date: Tue, 06 Oct 92 16:36:21 -0400
To: firewalls @ GreatCircle . COM (Firewalls mailing list)

 | * ease of configuration

Wellfleet filtering seems to work pretty well, but was a bit hard to
discover -- several features that are very powerful/useful seem to have been
added in some minor release to which we've either misplaced the docs, or
weren't documented...  (also, the "now you see it, now you don't" aspects of
the user interface drive me crazy).

Netblazer configuration was easier.  In addition, since one can trivially
edit the cnf file, I found it easier to create new filters on the Netblazer
than with the Wellfleet screen-oriented user interface.  (But then, I usually
prefer control file or command line interfaces for configuration)

 | * Types of filtering offered

Wellfleets (at least Link Nodes running 5.72) support multiple filters with
different levels of precedence per network interface.  Filters can specify
IP source or destination network/host addresses, source or destination port
ranges for UDP/TCP and user defined fields (specified by offset, length and
value ranges).  No test or monitoring facility that I can find, short of
watching the dropped packet count rise...

	Mark.


Indexed By Date Previous: More on bouncing email and mail-to-news gateways
From: Brent Chapman <brent @ GreatCircle . COM>
Next: Re: Quality of Wellfleet IP filtering
From: Brent Chapman <brent @ GreatCircle . COM>
Indexed By Thread Previous: Quality of Wellfleet IP filtering
From: msdrl!ajs @ uunet . UU . NET (Anthony Starks)
Next: Re: Quality of Wellfleet IP filtering
From: Brent Chapman <brent @ GreatCircle . COM>

Google
 
Search Internet Search www.greatcircle.com