Great Circle Associates Firewalls
(June 1997)
 

Indexed By Date: [Previous] [Next] Indexed By Thread: [Previous] [Next]

Subject: Re: Stateful Packet Filters vs. Proxies
From: geoffb @ NOJUNKunixpac . com . au (Geoff Breach)
Organization: Unixpac Pty Ltd, Sydney, Australia, +612 9953 8366
Date: Thu, 12 Jun 1997 01:04:16 GMT
To: firewalls @ greatcircle . com
Newsgroups: unixpac.lists.firewalls
References: <9706110016 . AA00967 @ sonic . nmti . com . nmti . com>

On Tue, 10 Jun 1997 19:16:15 -0500 (CDT), peter @
 baileynm .
 com (Peter da
Silva) wrote:
>> Except when it has to filter out an applet or some such.
>That's a bit more processing on the body of the document, but it can still
>be streamed and shouldn't add significantly to latency.

Zero processing on the body of the document. Filter on the
"MIME-Type:" header at the beginning of each document component, and
block the bad ones. No S&F required.

Geoff



References:
Indexed By Date Previous: Re: Packet filtering and TCP packets
From: Mike Hedlund <mike @ isi . net>
Next: Re: ssh proxy for fwtk
From: Benedikt Stockebrand <benedikt @ devnull . ruhr . de>
Indexed By Thread Previous: Re: Stateful Packet Filters vs. Proxies
From: peter @ baileynm . com (Peter da Silva)
Next: Re: Stateful Packet Filters vs. Proxies
From: Todd Hooper <todd . hooper @ alphawest . com . au>

Google
 
Search Internet Search www.greatcircle.com