Great Circle Associates Firewalls
(April 1995)
 

Indexed By Date: [Previous] [Next] Indexed By Thread: [Previous] [Next]

Subject: UDP
From: padgett @ tccslr . dnet . mmc . com (A. Padgett Peterson, P.E. Information Security)
Date: Sun, 16 Apr 95 20:48:41 -0400
To: "firewalls @ greatcircle . com"@UVS1.dnet.mmc.com

In their great wisdom, the framers of IP allowed that one size might not
fit all and so allow User Defined Protocols. The have their place but
IMNSHO, not across a firewall - if you need a 'wall, *by definition* you
must be able to control it. I have yet to find anything that I need
to do across a firewall that cannot be found within TCP except ICMP
(and am working on a proxy for that).

If am responsible for a gate, then am only going to allow things
that are understand across it and I am still learning. Does anyone out
there feel they know it all ? The more learned, the more I find that is 
not understood & UDPs are about as close to chaos as you can get

To me, I want some justification before more than PING, SMTP, Telnet,
FTP, NNTP, and HTTP cross the 'wall and have usually been able to
give people a way to do what they want within this. Would rather
provide an authenticated dial-up to the user if more is needed. Personally
cannot think of any legitemate requirement for FINGER that cannot be 
satisfied by a telephone call.

Am sorry if this is not a PC viewpoint and do not want to imply that
I am always happy with what is implimented. Just my opinion.

					Warmly,
						Padgett


Follow-Ups:
  • Re: UDP
    From: paul @ hawksbill . sprintmrn . com (Paul Ferguson)
Indexed By Date Previous: Improved detection of attack patterns and the time issue
From: fc @ all . net (Dr. Frederick B. Cohen)
Next: Re: Improved detection of attack patterns and the time issue
From: Benjamin Allan Smith <bens @ archimedes . vislab . navy . mil>
Indexed By Thread Previous: Re: Improved detection of attack patterns and the time issue
From: Benjamin Allan Smith <bens @ archimedes . vislab . navy . mil>
Next: Re: UDP
From: paul @ hawksbill . sprintmrn . com (Paul Ferguson)

Google
 
Search Internet Search www.greatcircle.com