Great Circle Associates Firewalls
(June 1997)
 

Indexed By Date: [Previous] [Next] Indexed By Thread: [Previous] [Next]

Subject: Re: Stateful Packet Filters vs. Proxies
From: marcvh @ aventail . com (Marc VanHeyningen)
Date: Wed, 11 Jun 1997 09:00:54 -0700
To: Firewalls @ greatcircle . com
In-reply-to: Your message of "Tue, 10 Jun 1997 10:55:14 MDT."

Geoff Mulligan writes:
> sjg @
 quick .
 com .
 au said:
> > Link level crypto, sure.  Not everyone likes that though. I was
> > refering to folk trying to use SSLftp, where the connection is
> > authenticated and encrypted at the application level.  Because a SPF
> > cannot look inside the payload in such a case, the dynamic opening of
> > ports will fail. 
> 
> And how is an SPF different from a proxy in this case, unless you are saying
> the proxy is participating in the encryption.

An application proxy would pretty much have to; if it were just relaying
encrypted traffic without decrypting and understanding it, it would
arguably be more appropriate to call it an generic proxy.

Generic proxies (like SOCKS) could also handle this case, but without
having to participate in the encryption, since there's a way for the proxy
to know about things like FTP data connections that need to be accepted
and the client to know what addresses to use.

-- 
Marc VanHeyningen                 marcvh @
 aventail .
 com
Internet Security Architect
Aventail                          http://www.aventail.com/



Indexed By Date Previous: Multiple port connections through PIX
From: "Brian Fraize" <brian . fraize @ rgsinc . com>
Next: question about routing on a firewall
From: jeff . oliver @ uleth . ca (Jeff Oliver)
Indexed By Thread Previous: Re: Stateful Packet Filters vs. Proxies
From: Bill Stout <stoutb @ pios . com>
Next: Re: Stateful Packet Filters vs. Proxies
From: Bill Stout <stoutb @ pios . com>

Google
 
Search Internet Search www.greatcircle.com