Great Circle Associates Firewalls
(March 1997)
 

Indexed By Date: [Previous] [Next] Indexed By Thread: [Previous] [Next]

Subject: ACL vulnerability
From: "Benvenuto, Vincent A." <vbenvenu @ faxint . com>
Date: Mon, 03 Mar 97 13:33:00 E
To: firewalls-digest <firewalls-digest @ greatcircle . com>

We are in the middle of a great debate as to the proper way to firewall 15 
remote sites.  We need to essentially open dedicated lines to our partners 
to allow incoming/outgoing FTP, X.400, and SMTP. One camp says ACLs in 
routers will be sufficient, another says stick with Firewall-1 and 
proliferate it like hell.  The cost difference network wide between the two 
approaches is huge.

Where can I find an (authoritative) threat analysis that describes the 
vulnerability of router based static ACLs (non-stateful inspection)?  Also, 
what methods (toolsets) are available to launch attacks through a router 
configured with ACLs?  any advice suggestions, etc appreciated.

Thanks in advance.

Vinnie B

Indexed By Date Previous: RE: UDP canceled by ISP
From: Russ <Russ . Cooper @ RC . on . ca>
Next: Re: Try it, it works!
From: "Loren Nozot" <lnozot @ iins . com>
Indexed By Thread Previous: Re: firewall architectures
From: Rick Smith <smith @ sctc . com>
Next: Re: ACL vulnerability
From: dharris @ kcp . com

Google
 
Search Internet Search www.greatcircle.com