Great Circle Associates Firewalls
(June 1997)
 

Indexed By Date: [Previous] [Next] Indexed By Thread: [Previous] [Next]

Subject: Re: Stateful Packet Filters vs. Proxies
From: "Simon J. Gerraty" <sjg @ quick . com . au>
Date: Sat, 7 Jun 1997 16:19:41 +1000 (EST)
To: Ryan Russell/SYBASE <Ryan . Russell @ sybase . com>
Cc: firewalls @ greatcircle . com
References: <199706060722 . AAA16788 @ notesgw2 . sybase . com>

Ryan Russell writes:
>Well, I finally got around to writing down my arguments
>on the above subject.  Check it out at:

>>I hope to convince the reader, to whatever degree I can, of the following: 

>>    1.Proxies are a special case of a SPF. 
>>    2.SPFs can be the more secure choice depending on the requirements. 
>>    3.Network address translation (NAT) can be considered a form of
>>	security on it's own.  

One thing to note - SPF and crypto do not mix.

I saw a case last week where users behind a PIX firewall could not use
an encrypted FTP, because the PIX box could not inspect the content of
PORT commands and allow the data ports to be connected to.

Solutions are:

1.	Use passive mode transfers.
2.	Turn off the filtering in the PIX :-)
3.	Do without crypto :-)

1 is obviously preferable if both sides can handle it - not always the
case.  The other two are not attractive at all.  If they'd been using
a proxy, they would not have had a problem.

--sjg
-- 
Simon J. Gerraty        <sjg @
 quick .
 com .
 au>

#include <disclaimer>   /* imagine something _very_ witty here */


Follow-Ups:
References:
Indexed By Date Previous: Re: PIX Question...
From: Chris Lonvick <clonvick @ cisco . com>
Next: [Fwd: Re: Microsoft Proxy Server]
From: Wong <smwong @ pdx . com . my>
Indexed By Thread Previous: Stateful Packet Filters vs. Proxies
From: Ryan Russell/SYBASE <Ryan . Russell @ sybase . com>
Next: Re: Stateful Packet Filters vs. Proxies
From: Geoff Mulligan <geoff @ mulligan . com>

Google
 
Search Internet Search www.greatcircle.com