Great Circle Associates Firewalls
(June 1996)
 

Indexed By Date: [Previous] [Next] Indexed By Thread: [Previous] [Next]

Subject: Re: Firewall-1 and Gauntlet
From: Darren Reed <avalon @ coombs . anu . edu . au>
Date: Mon, 3 Jun 1996 17:45:02 +1000 (EST)
To: todd @ momentum . com . au (Todd Hooper)
Cc: Firewalls @ GreatCircle . COM
In-reply-to: <v02130501add832a254c5 @ [203 . 2 . 238 . 134]> from "Todd Hooper" at Jun 3, 96 02:19:24 pm

In some mail from Todd Hooper, sie said:
> 
> Jean-Christophe Touvet <jct @
 edelweb .
 fr> writes:
> 
> > As far as I know, this is a Firewall-1 bug. The reason is that Gauntlet used
> >to split its PORT commands in two packets (two write() system calls). Since
> >Firewall-1's filtering code works only with one packet at once, it fails. TIS
> >guys wrote some patches to solve this problem (contact your Gauntlet reseller),
> >but IMHO that's really a packet filtering design problem: how do you inspect
> >data when it doesn't fit in the same packet ? Of course, you could keep data
> >in your sate machine, but in that case you've just written a proxy. Any
> >comments ?
> 
> Isn't that one of the issues (specifically, the problems with TIS and Gauntlet
> ftp) that Checkpoint fixed in Firewall-1 version 2.0d?

Do you know if they fixed the problem in general or just patched their ftp
proxy code to do the "PORT" command correctly ?

darren


References:
Indexed By Date Previous: Re: Raptor's Eagle Firewall
From: sameer @ wiproge . med . ge . com (Sameer )
Next: Re: Firewalls-Digest V5 #347
From: Danny Cox <dannyc @ gmap . leeds . ac . uk>
Indexed By Thread Previous: Re: Firewall-1 and Gauntlet
From: todd @ momentum . com . au (Todd Hooper)
Next: Re: Firewalls-Digest V5 #347
From: Danny Cox <dannyc @ gmap . leeds . ac . uk>

Google
 
Search Internet Search www.greatcircle.com