Great Circle Associates Firewalls
(June 1996)
 

Indexed By Date: [Previous] [Next] Indexed By Thread: [Previous] [Next]

Subject: Re: UDP filter tests
From: Bernhard Schneck <Bernhard_Schneck @ GeNUA . DE>
Date: Sun, 09 Jun 1996 17:41:50 +0200
To: Firewalls @ greatcircle . com

 > > What are some good methods to test UDP filters port by port?
 >
 > What about something like 'strobe' or 'netcat' ?

Well ... you often won't get back too much: there's no such thing
as a RST packet in UDP ... maybe you'll get ICMP port unreachable
but these may be supressed.

Best bet would be to put up a sniffer before and after the filter
element, hit it with the packets and see what's getting through
(or sent back to the source).

BTW, this is useful for TCP, too, especially when sending
non-standard format packets (like etcp and friends).

\Bernhard.

Indexed By Date Previous: Frame Relay, Cisco 2501, and packet filtering
From: Lenny Marlow <lmarlow @ conc . tdsnet . com>
Next: Central Management Station FW-1
From: "John H. Kerr" <jhkerr @ ashton . csc . com>
Indexed By Thread Previous: Re: UDP filter tests
From: Doug Hughes <Doug . Hughes @ Eng . Auburn . EDU>
Next: UDP filter tests
From: sameer @ wiproge . med . ge . com

Google
 
Search Internet Search www.greatcircle.com