Great Circle Associates Firewalls
(June 1997)
 

Indexed By Date: [Previous] [Next] Indexed By Thread: [Previous] [Next]

Subject: Re: Stateful Packet Filters vs. Proxies
From: Eric Vyncke <evyncke @ cisco . com>
Date: Thu, 12 Jun 1997 12:06:18 +0000
To: geoffb @ NOJUNKunixpac . com . au (Geoff Breach), firewalls @ GreatCircle . COM

At 01:04 12/06/97 GMT, Geoff Breach wrote:
>On Tue, 10 Jun 1997 19:16:15 -0500 (CDT), peter @
 baileynm .
 com (Peter da
>Silva) wrote:
>>> Except when it has to filter out an applet or some such.
>>That's a bit more processing on the body of the document, but it can still
>>be streamed and shouldn't add significantly to latency.
>
>Zero processing on the body of the document. Filter on the
>"MIME-Type:" header at the beginning of each document component, and
>block the bad ones. No S&F required.

That is not enough. Because the applet can be fetched by HTTP 1.0
or even 0.9 which do not use the MIME header.

So you have to parse the start of the document for the magic
bytes indicating a Java applet.

This is anyway a minor remark ;-) as this does not change
fundamentaly what you were writing

- Eric

  Eric Vyncke      
Technical Consultant              Cisco Systems Belgium SA/NV
Phone:  +32-2-778.4677             Fax:    +32-2-778.4300
E-mail: evyncke @
 cisco .
 com          Mobile: +32-75-312.458

Indexed By Date Previous: Re: Auto-Reply To Your Request...
From: David Alayeto Salvador <davidal @ sun2 . cps . unizar . es>
Next: Re: Stateful Packet Filters vs. Proxies
From: Benjamin Allan Smith <Benjamin . Smith @ sv . sc . philips . com>
Indexed By Thread Previous: Re: Stateful Packet Filters vs. Proxies
From: peter @ baileynm . com (Peter da Silva)
Next: Re: Stateful Packet Filters vs. Proxies
From: Benjamin Allan Smith <Benjamin . Smith @ sv . sc . philips . com>

Google
 
Search Internet Search www.greatcircle.com