Great Circle Associates Firewalls
(June 1997)
 

Indexed By Date: [Previous] [Next] Indexed By Thread: [Previous] [Next]

Subject: Re: Stateful Packet Filters vs. Proxies
From: "Craig I. Hagan" <hagan @ cih . com>
Date: Sun, 8 Jun 1997 10:05:02 -0400 (EDT)
To: Ryan Russell/SYBASE <Ryan . Russell @ sybase . com>
Cc: "Simon J. Gerraty" <sjg @ quick . com . au>, firewalls <firewalls @ GreatCircle . COM>
In-reply-to: <199706080120 . SAA28926 @ notesgw2 . sybase . com>
Reply-to: hagan @ cih . com

> Sure, an FTP proxy that can decrypt your
> encrypted FTP session will work, same as
> a SPF with the same features will.
> 
> If a SPF or a proxy can act as one endpoint
> of an ancrypted connection, it can watch
> for the port command and deal with it.
> 
> You seem to be under the impression that SPFs
> aren't capable of understaning the protocol
> being routed... if that were the case, the non-encrypted
> FTP session wouldn't work over the PIX box with NAT
> emabled, would it?  There is no reason that the SPF
> software can't be designed to act as an encryption 
> endpoint, but apparantly the PIX hasn't for FTP.
> 

I agree with you that you can make an SPF which can
handle any case that a proxy can. However, it is far
easier for the end user (read f/w implementor) to modify
proxy code such that it will match the requirements
of his/her site than it is for the end user to modify
an SPF.

-- craig


-------------------------------------------------------------------------------
Craig I. Hagan     "It's a small world, but I wouldn't want to back it up"
hagan @
 cih .
 com	        "True hackers don't die, their ttl expires"
  	"It takes a village to raise an idiot, but an idiot can raze a village"



Follow-Ups:
References:
Indexed By Date Previous: Re: Plug-gw- One to many relationship
From: Anton J Aylward <anton @ the-wire . com>
Next: RE: CheckPoint Firewall-1 V. 2.1
From: "Edkins, Rob - Axon AKL" <edkinsr @ axon . co . nz>
Indexed By Thread Previous: Re: Stateful Packet Filters vs. Proxies
From: Ryan Russell/SYBASE <Ryan . Russell @ sybase . com>
Next: Re: Stateful Packet Filters vs. Proxies
From: Darren Reed <avalon @ coombs . anu . edu . au>

Google
 
Search Internet Search www.greatcircle.com