Great Circle Associates Firewalls
(July 1997)
 

Indexed By Date: [Previous] [Next] Indexed By Thread: [Previous] [Next]

Subject: RE: Firewall on AIX
From: Roger Rea <rrea @ us . ibm . com>
Date: Mon, 7 Jul 1997 15:46:48 -0400
To: <gfaggion @ sif . cgs . it>
Cc: <Firewalls @ Greatcircle . Com>

>>Gabriele.................Perhaps you have not looked at the current
>version of
>>the IBM Firewall.  We are a much more complete firewall than other
>>firewalls,
>>offering not only filtering architechtures like Check Point, but also
>>Application Gateways and Circuit Level Gateways.  So you get three
>>firewalls in
>>one.

>PERHAPS YOU HAVEN'T LOOKED AT THE LAST 3 OR 4 VERSIONS OF THE CHECKPOINT
>FIREWALL.
>IT USES THE "STATEFUL INSPECTION" TECHNOLOGY TO FILTER ALL ISO LAYERS FROM
>THE NETWORK LAYER TO THE APPLICATION IN ONLY ONE PASS: THERE'A AN "INSPECT
>ENGINE" THAT USING DYNAMIC STAT TABLES ASSURES A FAST AND TRASPERENT
>INSPECTION.


Gabrielle asked if I was familiar with Check Point Stateful Inspection.
Certainly, I have looked at the product, and the marketing literature
surrounding it.  I've also followed their support forum for  the last 9 months,
and the numerous problems encountered by people trying to implement
Firewall-1.

Stateful Inspection filters on more than just header information, but it is
just filtering.  State tables can also introduce some problems, such as filling
up the state table.

Roger Rea
Firewall Product Market Manager, IBM
Phone: 919-543-1045                        FAX: 919-543-2693
Internet: rrea @
 us .
 ibm .
 com

Indexed By Date Previous: Re: Two ISP's to one DMZ
From: Paul Ferguson <pferguso @ cisco . com>
Next: javascript
From: "Chris A. Gill" <cgill @ dds-solutions . com>
Indexed By Thread Previous: RE: Firewall on AIX
From: firstcat @ lsli . com
Next: MTU Path Discovery w/proxy-based firewalls
From: uskanbye @ ibmmail . com

Google
 
Search Internet Search www.greatcircle.com