Great Circle Associates Firewalls
(June 1997)
 

Indexed By Date: [Previous] [Next] Indexed By Thread: [Previous] [Next]

Subject: Re: Stateful Packet Filters vs. Proxies
From: Mike Ordun <mro @ LANcomp . COM>
Date: Mon, 9 Jun 1997 12:22:33 -0400 (EDT)
To: firewalls @ greatcircle . com
In-reply-to: <Pine . LNX . 3 . 95 . 970609105308 . 20419A-100000 @ cih-gw . cih . com>

Have been following this discussion with a lot of interest as a reseller
of both SPF and proxy firewalls.  I happen to believe that both are
appropriate in different circumstances and customer need.  Nevertheless, I
am a little troubled by the claims that SPFs are inherently
insecure.  Let me present a challenge.  Lets compare some specific
commercial offerings -- Firewall-1 in one corner representing SPF and say
Gauntlet, Raptor, or ANS in the other representing the proxy approach. 
What I would like is some specific vulnerability that I cannot protect
myself from using the SPF as opposed to the proxy approach.  Again just
for emphasis, I am interested in specific vulnerabilities not just
restatement that in theory proxies are better because they deal with the
protocol at the application layer.  My somewhat cynical hypothesis, until
proven wrong with specific example, is that the majority of proxies are
really not better and in fact may be no more than an disguised SPF with
address translation.

Mike Ordun
mordun @
 lancomp .
 com



Follow-Ups:
References:
Indexed By Date Previous: Re: Stateful Packet Filters vs. Proxies
From: Ryan Russell/SYBASE <Ryan . Russell @ sybase . com>
Next: Re: Stateful Packet Filters vs. Proxies
From: Ryan Russell/SYBASE <Ryan . Russell @ sybase . com>
Indexed By Thread Previous: Re: Stateful Packet Filters vs. Proxies
From: Jarkko P Ahonen <jahonen @ cc . hut . fi>
Next: Re: Stateful Packet Filters vs. Proxies
From: Craig Brozefsky <craig @ onshore . com>

Google
 
Search Internet Search www.greatcircle.com