Great Circle Associates Firewalls
(September 1994)
 

Indexed By Date: [Previous] [Next] Indexed By Thread: [Previous] [Next]

Subject: Re: Firewall-1
From: crow!rik @ uunet . uu . net (Rik Farrow 602 282 0242 MST)
Date: Wed, 14 Sep 94 12:56:11 MST
To: uworld!uunet!znanost . mz . hr!gaus @ uunet . uu . net
Cc: uworld!uunet!greatcircle . com!firewalls @ uunet . uu . net
Reply-to: crow!rik @ uunet . uu . net

Gaus:

I did have some negative things to say about Firewall-1.  Most were in
a parapgraph toward the end, which was removed by the magazine's staff
so the story would finish on that page (aren't magazines great!):

[The deleted paragraph]
FireWall-1 drops source routed packets
by default, which is good for security, but may be bad if you need to use
source routing to contact certain difficult-to-reach sites.  Other firewall
implementations also offer improved authentication using one-time passwords--
something FireWall-1 currently does not support.  Finally, the nice GUI-
interface could lead a novice system administrator into a false sense of
security.  It is quite possible to permit potentially dangerous services,
like NFS, through CheckPoint's FireWall-1.  While FireWall-1 works great with
outgoing NFS, it won't protect against incoming attacks on NFS based on improperconfiguration of computers behind the firewall.`
[End]

Rik Farrow
rik @
 uworld .
 com 


Indexed By Date Previous: Re: writing packet filters.
From: jim @ Tadpole . COM (Jim Thompson)
Next: Logging Routers
From: mjs @ tiaa . org (marty shannon)
Indexed By Thread Previous: Re: Firewall-1
From: Brent @ GreatCircle . COM (Brent Chapman)
Next: TIS on BSD/386
From: Olga Aronov <oxa @ melba . bby . com . au>

Google
 
Search Internet Search www.greatcircle.com