Nmap Security Scanner
*Intro
*Ref Guide
*Install Guide
*Download
*Changelog
*Book
*Docs
Security Lists
*Nmap Hackers
*Nmap Dev
*Bugtraq
*Full Disclosure
*Pen Test
*Basics
*More
Security Tools
*Pass crackers
*Sniffers
*Vuln Scanners
*Web scanners
*Wireless
*Exploitation
*Packet crafters
*More
Site News
Site Search:
Exploit World
Advertising
About/Contact
Credits
Sponsors:
edgeos



Firewall Wizards: Re: Comparisons between Router ACLs and Firewalls

Re: Comparisons between Router ACLs and Firewalls

From: David Pick <d.m.pick_at_qmul.ac.uk>
Date: Thu, 01 Jan 2004 23:16:48 +0000

There are several different "firewall" technologies that work
at different layers in the protocol stack. One of these is
"packet filtering" and router ACLs are just one particular
implementation of this general technique. They are, in the
real world, an important implementation because there are
usually more routers than there are firewalls in a network
and using this allows more conotrol points to be used and also
allow for more depth to your defences.

In the network I control at my place of work we're replacing
Cisco routers by PCs running FreeBSD and IPFilter so that we
can have better controls at more levels in the protocol stack
than is provided by simple ACLs.

-- 
	David Pick
_______________________________________________
firewall-wizards mailing list
firewall-wizards_at_honor.icsalabs.com
http://honor.icsalabs.com/mailman/listinfo/firewall-wizards
Received on Jan 03 2004
[ Nmap | Sec Tools | Mailing Lists | Site News | About/Contact | Advertising | Privacy ]
edgeos