Great Circle Associates Firewalls
(February 1998)
 

Indexed By Date: [Previous] [Next] Indexed By Thread: [Previous] [Next]

Subject: RE: Firewalls-Digest V7 #51
From: Scott Robert Lenz <scott @ neologics . com>
Date: Tue, 3 Feb 1998 13:22:44 -0700
To: "Firewalls @ GreatCircle . COM" <Firewalls @ GreatCircle . COM>

Is this on an NT server? If so, IP forewarding opens up a large hole inside 
any security perimeter. Although I am not familiar enough with Checkpoint 
to know how it intercepts packets, I am surprised that they say that 
forewarding must be active. Even Microsoft states that when using thier MS 
proxy server, that IP forewarding MUST be disabled.



-----Original Message-----
From:	Kunal Choudhary [SMTP:kunalc @
 access .
 digex .
 net]
Sent:	Tuesday, February 03, 1998 8:01 AM
To:	Firewalls @
 GreatCircle .
 COM
Subject:	Re: Firewalls-Digest V7 #51

Hi all,

I've been told by Checkpoint support that v3.0b needs ip forwarding
turned on at the bastion host to work. The assure me that this is
completely safe, since the firewall inspects all packets anyway. I find
this surprising, esp considering that v2.1 never required this. Any
feedback will be appreciated.

Thanks

Kunal Choudhary


Follow-Ups:
Indexed By Date Previous: Re: Sniffer tools
From: Doug Hughes <Doug . Hughes @ Eng . Auburn . EDU>
Next: Re: Firewalls-Digest V7 #51
From: Stepken <stepken @ www . firmen-info . de>
Indexed By Thread Previous: Re: Firewalls-Digest V7 #51
From: Stepken <stepken @ www . firmen-info . de>
Next: RE: Firewalls-Digest V7 #51
From: Ming Lu <mlu @ privsys . gip . net>

Google
 
Search Internet Search www.greatcircle.com