Great Circle Associates Firewalls
(January 1995)
 

Indexed By Date: [Previous] [Next] Indexed By Thread: [Previous] [Next]

Subject: Re: screend
From: "Jim.Shaw" <Jim . Shaw @ actrix . gen . nz>
Date: Tue, 24 Jan 1995 07:33:12 +1300 (NZDT)
To: mjr @ tis . com (Marcus J Ranum)
Cc: firewalls @ greatcircle . com
In-reply-to: <9501230057 . AA00946 @ tis . com> from "Marcus J Ranum" at Jan 22, 95 08:04:40 pm

> 
> > We have a screend filter (from DEC).
> > In the Firewalls and Internet Security book on p. 66 it says that with
> > screend there is no protection against address-spoofing.
> 
> 	The issue is that screend (like many screening systems)
> doesn't have the ability to filter based on where the traffic CAME
> from rather than from where it CLAIMS to come from. Newer versions
> of routers can do this, and I STRONGLY RECOMMEND that anyone with
> a router-based firewall upgrade their ROMs.
> 
> 	Suppose I have a screening router with 2 interfaces, le0 and
> le1, where le1 is the "outside" and le0 is the "inside". Suppose my
> inside net is 192.33.112 and I tell the router it can "route anything
> from 192.33.112 to anyplace" but "only allow incoming traffic to
> go to my bastion 192.33.112.117" -- the flaw in the system is that
> the router has no idea if the traffic came in on le0 or le1. What
> if I have someone fake a packet so it comes in on le1 (the outside)
> claiming to come from 192.33.112.110, which the bastion trusts?
> OOOOoooops.
> 

I can see how a packet could get INTO a "protected" net based on this
method but the router wouldn't route the response, unless source routing
was used. That would preclude TCP sessions. Can a UDP packet be used to
do any damage if there is no return path possible? 

Or am I missing something ?

Jim


Follow-Ups:
  • Re: screend
    From: lavondes @ tidtest . total . fr (Michel Lavondes)

References:
Indexed By Date Previous: Spoof in our log?
From: labatt @ disaster . com (Chris Labatt-Simon - D&D Consulting)
Next: Re: RFD: comp.security.firewalls
From: mac @ Intellistor . COM (Mark Carlson)
Indexed By Thread Previous: Re: screend
From: robp @ anubis . network . com (Rob Peglar)
Next: Re: screend
From: lavondes @ tidtest . total . fr (Michel Lavondes)

Google
 
Search Internet Search www.greatcircle.com