Great Circle Associates Firewalls
(April 1997)
 

Indexed By Date: [Previous] [Next] Indexed By Thread: [Previous] [Next]

Subject: Re: AW: Opinions on Cisco PIX product?
From: Todd Truitt <Todd . Truitt @ evolving . com>
Date: Thu, 24 Apr 1997 13:21:14 -0600 (MDT)
To: bc17684 @ 90 . deere . com (Bertrum Carroll)
Cc: rhelmich @ pecos . de, elroy @ kcsun3 . kcstar . com, firewalls @ GreatCircle . COM
In-reply-to: <335E0E6E . 7BDC @ 90 . deere . com> from "Bertrum Carroll" at Apr 23, 97 08:28:14 am

-----BEGIN PGP SIGNED MESSAGE-----


three additional notes:

1.  PIX uses stateful inspection to verify connection requests
	to effectively reduce the chance of a successfull DOS
	attack.

2.  Since the PIX uses the micor-kernel, it can handle *many*
	more connection requests than full blown OS firewall's.

> 1.  The product is new and is still maturing, upgrades are coming pretty
> quick.
3.  Among these upgrades, as I understand it,  are a) more IOS like
	command set and b) web based config/management along the lines
	of the successful NETSYS tools.

- --Todd

'Bertrum Carroll once said:'
> Your #3 is not quite right.
> You can add at least one additional card the the PIX.

> I'll add a few more comments.
> 2.  The docs are not the best but there is not much to configuring a
> PIX.
> 3.  The logging need work but there is a syslog monitor you can get for
> the PIX that looks (not using it yet) pretty good.
> 4.  The support team has really gone all out to answer my silly
> questions in the past.
> 5.  I will agree the configurablility is limited but as a "firewall" the
> ease in configuration is not really a flaw.

> Safe Surfin


-----BEGIN PGP SIGNATURE-----
Version: 2.6.2

iQB1AwUBM1+yps9y1J+ua2vxAQHHJQMAla3v/srzO8xWbWJWIJzg6xjChAkHoERT
Udci/NaAcGe3yxtKQcKQnyvl2xXCI7gZ4Uk/NTEkz13Q7cTVYBnSFfvSk2Om3vt4
o7NDR2QwNqnqh0KIv+XZtPT+ozmDV0Zp
=YhQg
-----END PGP SIGNATURE-----


References:
Indexed By Date Previous: Re: Virus Protection at the Firewall
From: Bertrum Carroll <bc17684 @ 90 . deere . com>
Next: Re: [FW1] FW-1 and switching hubs (was: Solstice Firewall-1 and Netscape FTP)
From: Todd Truitt <Todd . Truitt @ evolving . com>
Indexed By Thread Previous: Re: AW: Opinions on Cisco PIX product?
From: Bertrum Carroll <bc17684 @ 90 . deere . com>
Next: Java applets and Netscape Navigator
From: david . stevens @ littlewoods . co . uk

Google
 
Search Internet Search www.greatcircle.com