Great Circle Associates Firewalls
(December 1992)
 

Indexed By Date: [Previous] [Next] Indexed By Thread: [Previous] [Next]

Subject: Re: packet filter metalanguage
From: Brent Chapman <brent @ GreatCircle . COM>
Date: Fri, 11 Dec 92 10:24:32 -0800
To: Firewalls @ GreatCircle . COM
In-reply-to: Your message of Sat, 5 Dec 1992 14:41:00 -0800

Brian Lloyd <brian @
 nic1 .
 barrnet .
 net> writes:

# I agree Lars, but it is even simpler than that.  We just need to convince
# router manufacturers what is necessary and sufficient for specifying filter
# rules.  It has been *VERY* difficult to get router manufacturers to listen.

Right.  I'm willing to cope with differences in specification syntax
and semantics, as long as I can specify roughly the same things.

# Atomic filters specs for IP/TCP/UDP need to encompass the following
# elements:
# 
# 1.  Interface
# 2.  Direction (inbound/outbound on interface)
# 3.  Source IP address
# 4.  Source IP address mask
# 5.  Destination IP address
# 6.  Destination IP address mask
# 7.  Protocol (UDP, TCP, ICMP, etc.)
# 8.  Source port [range]
# 9.  Destination port [range]
# 10. Pass/reject the packet if it matches the filter
# 
# For ICMP you need to substitute the following for 8 & 9 above:
# 
# 8'. ICMP message type
# 9'. ICMP message subtype

This is, I believe, a correct "least common denominator" that I'd be
absolutely thrilled if all vendors implemented.

# To construct rule sets you need to order the atomic filter specs.  Due to
# possible undesired interactions the filter "builder" needs to be able to
# order the atomic filter rules to produce the final rule set.

This is an absolutely critical point.  Building filters is already
hard enough; I don't need the vendors to "help" me by making me
second-guess what order their router is going to apply my rules in.


-Brent
--
Brent Chapman                                   Great Circle Associates
Brent @
 GreatCircle .
 COM                           1057 West Dana Street
+1 415 962 0841                                 Mountain View, CA  94041


Indexed By Date Previous: Re: Firewalls Digest V1 #42
From: Brent Chapman <brent @ GreatCircle . COM>
Next: Re: Fields in filter specification
From: Brent Chapman <brent @ GreatCircle . COM>
Indexed By Thread Previous: Re: packet filter metalanguage
From: Steve Kennedy <steve @ gbnet . org>
Next: Re: packet filter metalanguage
From: jim @ tadpole . com (Jim Thompson)

Google
 
Search Internet Search www.greatcircle.com