Great Circle Associates Firewalls
(December 1994)
 

Indexed By Date: [Previous] [Next] Indexed By Thread: [Previous] [Next]

Subject: information on NetGate packet filtering firewall
From: charisse @ SmallWorks . COM (Charisse Castagnoli)
Date: Sat, 17 Dec 94 14:08:13 CST
To: 100436 . 3361 @ compuserve . com, firewalls @ greatcircle . com

NetGate(TM)is a software firewall for SPARC based systems developed by
SmallWorks of Travis Co.    SmallWorks specializes in efficient 
networking utilities and custom software development for SunOS.

NetGate was designed to provide routing and filtering for networks of TCP/IP 
systems without requiring expensive, separately managed hardware.  It performs
filtering, logging and forwarding for a network or subnetwork of TCP/IP
based computers.  The extensible rules based system allows the administrator
to customize the firewall to allow or disallow packets into the network system.

Technical Overview:

	NetGate is a rule-based packet forwarding scheme for use on SPARC
	systems running SunOS 4.1.X.  Through the use of NetGate, a SPARC
	system can become a sophisticated router, packet forwarder and
	firewall.

	NetGate examines each incoming packet and performs rule based 
	filtering on the packet before allowing the packet to be
	delivered to the network service or forwarded to the next system.

	NetGate operates by applying a set of administrator customized
	rules to each packet.  Packets may be forwarded, logged or
	dropped.  Filtering rules can be based on any combination of:
		
		source or destination IP address, 
		source or destination hostnames,
		networks or netgroups,
		protocols, and
		services

	NetGate maintains statistics for each rule and packet.  NetGate
	conveniently logs failed packets using the syslog facility.  Thus
	providing a convenient monitoring mechanism and allowing the
	administrator to utilize standard Unix utilities to implement
	escalation policies. 

Operation:

	NetGate executes inside the operating system, making it virtually
	un-spoofable.  As a kernel module, performance impact is minimal,
	since the packet filtering is done prior to presenting the errant
	packet to user space.  Saving processing time through the remainder
	of the protocol stack, and eliminating superfluous context switches.
	This is a distinct advantage over public domain "wrapper" programs,
	and other similar commercial products. 

	NetGate's simple command line interface allows the administrator to
	create time based access policies, through the use of cron(8).

Availability:

	NetGate is available for SunOS 4.1.X as either a binary installation,
	or in source code for the truly adventurous.  A single binary license
	is $1500.  Source Code is $2500.  Site, corporate-wide and 
	distributor licensing are also available.

	All shipments include 90 days support and maintenance, which 
	includes any updates released during that time.


For more information, or to contact a SmallWorks representative:

	Send email to: 		info @
 smallworks .
 com
	Or telephone/fax to:	512 338 0619


Follow-Ups:
Indexed By Date Previous: Suggestion for firewall for deliberately insecure company?
From: jet @ abulafia . genmagic . com (J. Eric Townsend)
Next: smap
From: Terry . Nelms @ lddsnet . com (Terry Nelms (Manager Systems Integrity))
Indexed By Thread Previous: Re: Suggestion for firewall for deliberately insecure company?
From: rmck @ sandfiddler . paragon-systems . com (Bob McKisson)
Next: modload'able packet filter for SunOS 4.1.x
From: Darren Reed <avalon @ coombs . anu . edu . au>

Google
 
Search Internet Search www.greatcircle.com