Great Circle Associates Firewalls
(July 1995)
 

Indexed By Date: [Previous] [Next] Indexed By Thread: [Previous] [Next]

Subject: Re: Sending replies to blocked packets.
From: paul @ hawksbill . sprintmrn . com (Paul Ferguson)
Date: Sat, 8 Jul 1995 19:27:25 -0500 (EST)
To: ds3721 @ strydr . com (David Schnardthorst)
Cc: avalon @ coombs . anu . edu . au, blymn @ awadi . com . AU, Firewalls @ GreatCircle . COM
In-reply-to: <199507082251 . RAA00199 @ strydr . strydr . com> from "David Schnardthorst" at Jul 8, 95 05:51:09 pm

> 
> If the firewall is being monitored the way that it should be, the longer it
> takes for the cracker to get in, the more time you will have to react to
> the problem.  The logs should be monitored several times a day.  This can
> tell you whether or not someone is trying to get in.  By extending the time
> that it would take for them to scan all of the ports, you will have a much
> better chance of stopping them before they get in.
>

There is an alternative train of though that it doesn't really pay to
monitor port scans, it takes too much time and resources, and if you've
got 'em blocked anyway, who cares?

I'll agree that it pays to monitor the ports that you do NOT have blocked,
but who cares about scans on the networks, hosts or services that are
unavailable?

Devil's advocate,

- paul

 
_______________________________________________________________________________
Paul Ferguson                         
US Sprint                                          tel: 703.689.6828
Managed Network Engineering                   internet: paul @
 hawk .
 sprintmrn .
 com
Reston, Virginia  USA                             http://www.sprintmrn.com 


Follow-Ups:
References:
Indexed By Date Previous: Re: Sending replies to blocked packets.
From: David Schnardthorst <ds3721 @ strydr . com>
Next: Re[2]: Sending replies to blocked packets.
From: brian @ ilinx . ilinx . com (Brian J. Murrell)
Indexed By Thread Previous: Re: Sending replies to blocked packets.
From: David Schnardthorst <ds3721 @ strydr . com>
Next: Re: Sending replies to blocked packets.
From: blymn @ awadi . com . AU (Brett Lymn)

Google
 
Search Internet Search www.greatcircle.com