Great Circle Associates Firewalls
(January 1998)
 

Indexed By Date: [Previous] [Next] Indexed By Thread: [Previous] [Next]

Subject: Re[2]: Stateful Inspection Anyone? Explore your options.
From: Oliver Lau <lau @ skp . de>
Date: Wed, 07 Jan 1998 09:28:02 +0100
To: Gordon LaSane <glasane @ gdsconnect . com>
Cc: <firewalls @ GreatCircle . COM>, Martin Sauer <ms @ majestix . skp . de>
In-reply-to: <A1F2B23A4F10D1118DDB00A0C9193FCF016C01 @ ALTOS>
References: <A1F2B23A4F10D1118DDB00A0C9193FCF016C01 @ ALTOS>

Greetings, Gordon!

On Tue, 6 Jan 1998 16:37:03 -0500
Gordon LaSane <glasane @
 gdsconnect .
 com> wrote:

|  One of the biggest complaints about stateful inspection is that if the
|  state table becomes corrupt, the network could become vulnerable to the
|  outside.

You surely haven't had a look inside stateful inspection firewalls, have
you? You have to distinguish between two possibilities on how tables
can become corrupt:

	1.) accidentally deleted entries
	2.) forged entries

Accidentally deleted entries only have one effect: active connections
become inactive and therefore further packets belonging to this
connections could no longer traverse the firewall.

Forged entries may have the effect you described. But this is a point
where we discuss the security of the firewall itself and not the
security services a firewall should provide for networks.

|
|  [snipped commercial offerings]
|



Regards,
Oliver Lau
[CTO]
Sauer und Partner GmbH, NetzwerkTechnologie und Sicherheit
Dietrich-Bonhoeffer-Strasse 1-3, 35037 Marburg, Germany
fon: +49 6421 938300, fax: +49 6421 938390, URL: http://www.skp.de/
PGP-Fingerprint: 6696 C8B6 F351 A381  D1C9 BC41 98F2 6DE3


Follow-Ups:
References:
Indexed By Date Previous: Re: Firewall for ISP
From: Andre van der Lans <andre . van . der . lans @ inet . unisource . nl>
Next: LanOptics Guardian???
From: "Takacs Istvan" <anonymus @ mail . matav . hu>
Indexed By Thread Previous: RE: Stateful Inspection Anyone? Explore your options.
From: William Cooper <cooper @ io . com>
Next: Re: Re[2]: Stateful Inspection Anyone? Explore your options.
From: Rick Murphy <rmurphy @ itm-inst . com>

Google
 
Search Internet Search www.greatcircle.com