Great Circle Associates Firewalls
(July 1996)
 

Indexed By Date: [Previous] [Next] Indexed By Thread: [Previous] [Next]

Subject: Re: Stateful Packet Screens
From: Mike Shaver <shaver @ neon . ingenia . ca>
Date: Tue, 2 Jul 1996 12:21:08 -0400 (EDT)
To: avalon @ coombs . anu . edu . au (Darren Reed)
Cc: shaver @ neon . ingenia . ca, Ryan . Russell @ sybase . com, firewalls @ GreatCircle . COM
In-reply-to: <199607020857 . BAA28063 @ miles . greatcircle . com> from "Darren Reed" at Jul 2, 96 06:54:52 pm

Thus spake Darren Reed:
> Dealing with a 1MB e-mail is going to be difficult, in kernel space.

1) Who says it has to be in kernel space?
2) Who says there has to be a kernel space at all?  We're not limited
to Unix here.

> FW-1 is a bit more advanced: it snoops RPC traffic and learns about
> RPC services that way rather than any configuration file.

Wow, that almost sounds like it's processing stuff at the application
level! =)

Mike

-- 
#> Mike Shaver (shaver @
 ingenia .
 com) Ingenia Communications Corporation <#
#> Paranoid for money.                            Sarcastic for kicks. <#
#>                                                                     <#
#> "They already *KNOW* I am a whacko, Karen.                          <#
#>                  That doesn't mean I am *WRONG*." -- mjr @
 clark .
 net  <#


References:
Indexed By Date Previous: Re: Hardware requirements of Firewall-1
From: ap @ netix . it (Aldo Pannocchia)
Next: Re: /etc/shadow encryption
From: Michael Ryan <mike @ networx . ie>
Indexed By Thread Previous: Re: Stateful Packet Screens
From: Darren Reed <avalon @ coombs . anu . edu . au>
Next: Re: NT Backoffice "Catapult" firewall certified?
From: peter @ baileynm . com (Peter da Silva)

Google
 
Search Internet Search www.greatcircle.com