Great Circle Associates Firewalls
(October 1997)
 

Indexed By Date: [Previous] [Next] Indexed By Thread: [Previous] [Next]

Subject: RE: sex, lies, and firewall code
From: Rick Murphy <rick @ paimail . com>
Date: Sun, 19 Oct 1997 17:01:28 -0400
To: "Craig S. Wright" <craig . wright @ asx . com . au>
Cc: "'firewalls @ GreatCircle . COM'" <firewalls @ GreatCircle . COM>
In-reply-to: <01BCDC8C . B5A23550 @ aragon>

At 12:44 PM 10/19/97 +1000, Craig S. Wright wrote:
>	The issues should not be based on proxy vs filter gateways, rather the
> two need to be deployed together (note that TIS uses a packet filter too,
so >both FW-1 and TIS are hybrids).
Gauntlet uses a packet *screen* for enforcing anti-spoofing rules and for
support of transparency. This is not a packet filter. (I'm not arguing
semantics here - a packet FILTER allows packets to forward across the
firewall. The Gauntlet packet SCREEN only denies packets or permits them
to go to proxies.)
	-Rick



References:
Indexed By Date Previous: Re: sex, lies, and firewall code
From: Rick Murphy <rick @ paimail . com>
Next: Re: sex, lies, and firewall code
From: Frederick M Avolio <avolio @ tis . com>
Indexed By Thread Previous: RE: sex, lies, and firewall code
From: "Craig S. Wright" <craig . wright @ asx . com . au>
Next: sex, lies, and firewall code
From: bwa @ shadow . dbapic . com . au (Barry W. Anderson)

Google
 
Search Internet Search www.greatcircle.com