Great Circle Associates Firewalls
(August 1996)
 

Indexed By Date: [Previous] [Next] Indexed By Thread: [Previous] [Next]

Subject: Re: Info World Firewall Articles
From: Steve Kotsopoulos <steve @ ecf . toronto . edu>
Organization: University of Toronto, Engineering Computing Facility
Date: Wed, 7 Aug 1996 12:04:11 -0400
To: firewalls @ greatcircle . com
In-reply-to: <32066928 . 1297 @ us . checkpoint . com>
References: <199608021813 . OAA25474 @ phoenix . iss . net>

In article <32066928 .
 1297 @
 us .
 checkpoint .
 com> Barbara Jaarsma wrote:
>The following is Checkpoint's official response to your query re: the=20
>InfoWorld article.  -Barb
>
>Dear Check Point Resellers & Customers,
>
>A product comparison of firewall products which included CheckPoint
>FireWall-1 appeared in the July 29 issue of InfoWorld magazine.  While
>the review was overall highly favorable, it incorrectly stated that
>during the system boot process, the system is vulnerable to attack.  We
>would like to assure you that this information is inaccurate and that we
>reached agreement with InfoWorld to print a correction in next week=92s
>issue.
>
>During the testing process, the InfoWorld reviews staff did not follow
>the company=92s recommended boot procedures which are specified on=20
>pages 16-3 and 16-4 in the in the CheckPoint FireWall-1 user manual. =20
>When installing the product, the publication=92s reviews staff did not=20
>turn off the IP forwarding function.

I would seriously question the security of a firewall that
has IP forwarding turned on by default, and requires you to
DO SOMETHING to turn it off. Common wisdom would have it disabled by
default (at least), or even rip the code out from the kernel (preferred).

Most Unix systems are unfortunately insecure out of the box.
We should expect all good firewalls to be highly secure out of the box.
-- 
Steve Kotsopoulos  M.Eng.                         steve @
 ecf .
 toronto .
 edu
Systems Analyst   Engineering Computing Facility, University of Toronto
http://www.ecf.toronto.edu/~steve/


Follow-Ups:
References:
Indexed By Date Previous: CERN V3.0A Release Notes
From: avv @ gumby . sp . TRW . COM (Anthony V. Vitale)
Next: Re: Intelligent networks
From: Joshua Cole <josh @ itp . eds . com>
Indexed By Thread Previous: Re[2]: Info World Firewall Articles
From: Brian Murrell <Brian_Murrell @ bctel . net>
Next: Re: Info World Firewall Articles
From: marchany @ vtserf . cc . vt . edu

Google
 
Search Internet Search www.greatcircle.com