Great Circle Associates Firewalls
(July 1994)
 

Indexed By Date: [Previous] [Next] Indexed By Thread: [Previous] [Next]

Subject: Re: How About Netblazers?
From: Brent Chapman <brent @ mycroft . GreatCircle . COM>
Date: Tue, 12 Jul 1994 09:37:58 -0700
To: "William C. Fenner" <fenner @ cmf . nrl . navy . mil>
Cc: johns @ oxygen . house . gov (John Schnizlein), firewalls @ greatcircle . com, titan!gustavo @ enuucp . eas . asu . edu
In-reply-to: Your message of Tue, 12 Jul 94 08:33:56 -0400

"William C. Fenner" <fenner @
 cmf .
 nrl .
 navy .
 mil> writes:

# On Fri, 8 Jul 1994 14:45:47 -0400  John Schnizlein wrote:
# > As filter statements are added they go at the top (highest precedence)
# > of the list (the opposite of Cisco) except for the default specification,
# > which is at the end if present.
# 
# Filters actually get inserted into the list in sorted order by number of
# bits in the netmask.  You are supposed to be able to enter filters in any
# order and they will still come out the same, but there are some bugs, at
# least in their latest release, 2.3 .
# 
#   Bill

Those bugs have been there forever; I've given up on them ever getting
fixed.

This "feature" of the NetBlazer was the original impetus
behind the "order dependency" example in my "Network (In)Security
through IP Packet Filtering" paper from a couple of years ago
(available for anonymous FTP:
    ftp://ftp.greatcircle.com/pub/firewalls/papers/chapman/pkt_filtering.ps.Z
).


-Brent
--
Brent Chapman         | Great Circle Associates  | Call or email for info about
Brent @
 GreatCircle .
 COM | 1057 West Dana Street    | upcoming Internet Security 
+1 415 962 0841       | Mountain View, CA  94041 | Firewalls Tutorial dates

Indexed By Date Previous: re: Vendor Recommendations
From: Marcus J Ranum <mjr @ tis . com>
Next: Re: How About Netblazers?
From: Brent Chapman <brent @ mycroft . GreatCircle . COM>
Indexed By Thread Previous: Re: How About Netblazers?
From: "William C. Fenner" <fenner @ cmf . nrl . navy . mil>
Next: Re: How About Netblazers?
From: Brent Chapman <brent @ mycroft . GreatCircle . COM>

Google
 
Search Internet Search www.greatcircle.com