Great Circle Associates Firewalls
(February 1997)
 

Indexed By Date: [Previous] [Next] Indexed By Thread: [Previous] [Next]

Subject: Re: Checkpoint
From: "Chris Kostick" <christopher . t . kostick @ cpmx . saic . com>
Date: Thu, 13 Feb 1997 21:18:34 -0800
To: <posa @ isb . comsats . net . PK>
Cc: <firewalls @ greatcircle . com>

> Hello.. I am new to this list. Could someone please tell me the benefits
> of Checkpoint Firewalls?

Advantage: Primarily a filtering router with stateful inspection.
Disadvatage: Primarily a filtering router with stateful inspection.

Filtering provides a nice benefit of speed and flexibility. Nice
flexibility.
But sometimes a service should not be allowed through directly--mail for
one.
This is where proxies are important.

Firewall v3.0 is coming out with more proxy support, and from my
understanding
they're doing it the right way instead of just employing a proxy for
authentication only. An all filtering solution like FW-1 started out as is
not the right answer and won't meet everyone's needs. An all proxy solution

like TIS Gauntlet started out as is not the right answer either. Both
vendors
are moving toward stable Hybrid solutions. This, in my view, is how a
firewall
should be.

--
Chris Kostick
SAIC-Center for Information Security Technology

Indexed By Date Previous: Re: Split DNS - Another way
From: Anton J Aylward <anton @ the-wire . com>
Next: Re: Spit DNS - Another way
From: "James R Grinter" <jrg @ gbnet . net>
Indexed By Thread Previous: Re: Checkpoint
From: Matt Wallace <mwallace @ netcom . com>
Next: fwd: fwdom: Failed to create pipe: Too many open files
From: etxrosd @ nmac . ericsson . se (Robert Stahlbrand)

Google
 
Search Internet Search www.greatcircle.com