Great Circle Associates Firewalls
(July 1997)
 

Indexed By Date: [Previous] [Next] Indexed By Thread: [Previous] [Next]

Subject: Re: Why controlling Source IP address on a Firewall?
From: "Jay K. Bahel" <jbahel @ mcs . net>
Date: Thu, 31 Jul 1997 23:48:18 -0500
To: "Magossa'nyi A'rpa'd" <mag @ bunuel . tii . matav . hu>, "Santi Ribas" <santi @ browns . co . uk>
Cc: <firewalls @ GreatCircle . COM>

Is it true that hackers cannot spoof illegal TCPIP addresses - for those
clients using network address translation?

-Jay

----------
> From: Magossa'nyi A'rpa'd <mag @
 bunuel .
 tii .
 matav .
 hu>
> To: Santi Ribas <santi @
 browns .
 co .
 uk>
> Cc: firewalls @
 GreatCircle .
 COM
> Subject: Re: Why controlling Source IP address on a Firewall?
> Date: Monday, July 28, 1997 2:50 AM
> 
> On Thu, 24 Jul 1997, Santi Ribas wrote:
> 
> > If the Source IP address is easily spoofed, why implement Source IP
> > Address control in a Firewall?
> > 
> > The only difference I see is that by controlling it, a hacker will
> > probably need to check for TCP Sequence Prediction, create a deny of
> > service to the real client and change the source IP address of the
> > packet.
> Not exactly. If you have a good network setup, you can have address
> ranges which can't be spoofed from "outside" (not talking now about
social
> engineering, and already cracked systems inside).
> One example is a host in the same subnet, where you can wire in that ARP
> entry (which in fact can be spoofed as well, but iff the enemy is already
on
> that subnet).
> Yes, only src IP address control is not an ultimate solution, but it
seems
> enough when you want to decide wether your http proxy requested that http
> connection to the outside, and it is written in the corporate policy that
IP
> spoofing is illegal.
> 
> ---
> GNU GPL: csak tiszta forrásból
> 
> 

Indexed By Date Previous: Re: [FW1] Virus Protection on FW-1
From: "Jay K. Bahel" <jbahel @ mcs . net>
Next: Re: FW-1 logs....is this an attack...?
From: proff @ suburbia . net
Indexed By Thread Previous: Re: Why controlling Source IP address on a Firewall?
From: "Magossa'nyi A'rpa'd" <mag @ bunuel . tii . matav . hu>
Next: a general question
From: "Shakila Shayan" <S-SHAYAN @ KARUN . ipm . ac . ir>

Google
 
Search Internet Search www.greatcircle.com