At 12:44 PM 10/19/97 +1000, Craig S. Wright wrote:
> The issues should not be based on proxy vs filter gateways, rather the
> two need to be deployed together (note that TIS uses a packet filter too,
so >both FW-1 and TIS are hybrids).
Gauntlet uses a packet *screen* for enforcing anti-spoofing rules and for
support of transparency. This is not a packet filter. (I'm not arguing
semantics here - a packet FILTER allows packets to forward across the
firewall. The Gauntlet packet SCREEN only denies packets or permits them
to go to proxies.)
-Rick
References:
|
|