Great Circle Associates Firewalls
(November 1996)
 

Indexed By Date: [Previous] [Next] Indexed By Thread: [Previous] [Next]

Subject: Re: Re[2]: Cisco's PIX firewall
From: Matthew Howard <mhoward @ cisco . com>
Date: Wed, 27 Nov 1996 07:12:04 -0800
To: hagan @ cih . com, Chris Lonvick <clonvick @ cisco . com>
Cc: "Michael H. Warfield" <mhw @ wittsend . com>, Mark_Plesser_at_NYRAPO @ pcmailgw . ml . com, zaka @ tiac . net, lazar @ netevolve . com, firewalls @ GreatCircle . COM

At 08:36 AM 11/27/96 -0500, Craig I. Hagan wrote:
>> Cut-through Proxies on the PIX appear to the user to work in a somewhat
>> similar way.  When the PIX detects a new session starting of a protocol
>> which is knows about, it will complete the session and ask for proper
>> authentication.  The protocols which we currently support are telnet,
>> ftp, and http.  So, as the same example, when you telnet to something on
>> the Internet (unlike the typical proxy firewalls, you will use the IP
>> address of the actual device you want to get to; not the address of the
>> PIX), the PIX will get in the way of the session and ask for
>
>I had always heard such described as "transparent proxying"

The goal is to offer transparent user authentication while maintain session
state.  We also track tcp flags, tcp seq numbers and we randomize every tcp
session that goes through our stateful engine.  we have a hashed table that
functions very much like cross-bar switch that establishes a flow state.

typical proxy based firewalls fire off a process for every proxy session.
In typical cisco fashion we will add more knobs to this feature.  In some
sense, think of this as going from process switching to net flow switching.
  
Matt
>
>-- craig
>
>-------------------------------------------------------------------------------
>Craig I. Hagan     "It's a small world, but I wouldn't want to back it up"
>hagan @
 cih .
 com	        "True hackers don't die, their ttl expires"
>
>
>
>
> 
>
>
>


   Matthew Howard   
   Product Line Manager               mhoward @
 cisco .
 com
   Internet Business Unit             408-526-4720 (voice)
   Cisco Systems Inc.		      408-527-8122 (fax)
   170 West Tasman Drive  
   Building VM2 (corner of First & Vista Montana)                             
   San Jose, CA 95134


Indexed By Date Previous: Re: Firewall Training Courses
From: firstcat @ lsli . com
Next: RE: Redundant FW-1s in Parallel!?
From: "A. Ömer Köker" <omer @ superonline . net>
Indexed By Thread Previous: Re: Re[2]: Cisco's PIX firewall
From: "Craig I. Hagan" <hagan @ cih . com>
Next: RE: Cisco's PIX firewall
From: Ryan Russell/SYBASE <Ryan . Russell @ sybase . com>

Google
 
Search Internet Search www.greatcircle.com