Great Circle Associates Firewalls
(April 1997)
 

Indexed By Date: [Previous] [Next] Indexed By Thread: [Previous] [Next]

Subject: Borderware firewall...(if that's what you want to call it)
From: Jesse Whyte <jesse @ eac . com>
Organization: EAC Network Integrators
Date: Thu, 10 Apr 1997 14:11:44 -0400
To: firewalls @ greatcircle . com
Cc: firewall-1-mailinglist @ us . checkpoint . com
Reply-to: jesse @ eac . com

I have had to do some performance and security testing on the Borderware
firewall product over the last couple of weeks and I have some issues
that I wanted to address here...

1) We caused a kernel panic by flooding the firewall system itself with
ping ECHO_REQUESTS at less than T-1 bandwidth...

2) The default configuration loads a web server on port 80 for the
entire world to see...

3) The firewall doesn't discriminate between internal and external hosts
when it proxies, (ie, with a poor setup (the default setup), I can set
the proxy in my browser to the external interface of the proxy, then try
to go to the internal interface and the firewall will proxy me
there...another interesting side effect of this was that you can get
packets to the web management port 442)

Based on these results, I can't see how I would ever sully my reputation
by recommending this product.  Has anyone ever dealt successfully with
this product...Specifically, does anyone with Firewall-1 experience care
to comment on a comparison?  My comparison's results should be pretty
obvious, by now...

Thanks for your help and your advice,

Jesse
-- 
***********************************************************************
Jesse Whyte		EAC Network Integrators		
Security Analyst	Trumbull, CT
jesse @
 eac .
 com		http://www.eac.com
(203) 371-2441

Indexed By Date Previous: re: su root log
From: David Sacerdote <davids @ secnet . com>
Next: DNS server other than BIND?
From: Adam Shostack <adam @ homeport . org>
Indexed By Thread Previous: Re: Virus Alert
From: "Vitaly Vanchurin"<Vitaly_Vanchurin @ hmco . com>
Next: RE: Borderware firewall...(if that's what you want to call it)
From: Russ <Russ . Cooper @ RC . on . ca>

Google
 
Search Internet Search www.greatcircle.com