Great Circle Associates Firewalls
(January 1995)
 

Indexed By Date: [Previous] [Next] Indexed By Thread: [Previous] [Next]

Subject: Re: Firewall-1 and TCP Sequence Number Spoofing
From: Pug <pug @ arlut . utexas . edu>
Date: Fri, 27 Jan 1995 08:58:37 -0600 (CST)
To: D_Bauer%huac @ MWMGATE1 . mitre . org
Cc: steveg @ cseic . saic . com, firewalls @ GreatCircle . COM
In-reply-to: <199501271416 . JAA21298 @ mwunix . mitre . org> from "D_Bauer%huac @ MWMGATE1 . mitre . org" at Jan 27, 95 09:18:57 am

> One of the characteristics of an effective firewall is that ALL traffic--both 
> internal and external--pass through the firewall.  If the firewall "drops all 
> packets whose source and destination are both in the internal net", then 
> wouldn't this prevent the nodes on the internal net from communicating with one 
> another?

This would only prevent them from communicating if they are truly
misconfigured (I don't even know if you could do it without further
subnetting and contortions). If they are both on the same net/cable,
then they should have never been trying to talk through the firewall in
the firstplace. If they are subnetted, then they should have a default
route set to the local router. If the local router is the firewall (ie.
1 router, multiple interfaces), then they are not on the same network
anyway.

Ciao,

-- 
Richard Bainter          Mundanely     |    System Analyst        - OMG/CSD
Pug                      Generally     |    Applied Research Labs - U.Texas
 pug @
 arlut .
 utexas .
 edu  |  pug @
 bga .
 com  |  pug @
 eden .
 com  |  {any user} @
 pug .
 net
Note: The views may not reflect my employers, or even my own for that matter.


References:
Indexed By Date Previous: Re: FTP through firewall
From: bobk @ manzanita . DEV . 3Com . COM (Bob Konigsberg)
Next: Re: Router filtering not enough! (Was: Re: CERT advisory )
From: Jon Peatfield <J . S . Peatfield @ damtp . cambridge . ac . uk>
Indexed By Thread Previous: Re: Firewall-1 and TCP Sequence Number Spoofing
From: D_Bauer%huac @ MWMGATE1 . mitre . org
Next: Firewall-1 and TCP Sequence Number Spoofing
From: steveg @ cseic . saic . com (Stephen Harold Goldstein)

Google
 
Search Internet Search www.greatcircle.com