Nmap Security Scanner
*Intro
*Ref Guide
*Install Guide
*Download
*Changelog
*Book
*Docs
Security Lists
*Nmap Hackers
*Nmap Dev
*Bugtraq
*Full Disclosure
*Pen Test
*Basics
*More
Security Tools
*Pass crackers
*Sniffers
*Vuln Scanners
*Web scanners
*Wireless
*Exploitation
*Packet crafters
*More
Site News
Site Search:
Exploit World
Advertising
About/Contact
Credits
Sponsors:
edgeos



Firewall Wizards: Re: Firewalls & multicast- what's the choice?

Re: Firewalls & multicast- what's the choice?

From: Dale W. Carder <dwcarder_at_doit.wisc.edu>
Date: Tue, 01 Aug 2006 10:18:22 -0500

On Aug 1, 2006, at 6:41 AM, Bob Arthurs wrote:
> any special considerations for PIM / Multicast?
> what are the alternatives, when are they used, and what are their
> pros/cons.

There's 2 common ways that firewalls implement multicast support
(robustly). Some actually speak a multicast routing protocol, or
the other approach is to filter at layer 2, aka "transparent mode"
to stay out of the way.

Both are valid approaches. If you want to route on your firewall,
you probably need support for pim sparse mode. Don't accept only
dense mode or dvmrp implementation. I believe that recent releases
for cisco pix/asa have pim-sm. I personally favor transparent mode
and there are many vendors out there that can do it.

Now, for your ruleset you are going to have to do a bit of homework or
you will end up with a "default allow" acl. Are there only specific
groups you will let in? Are there only specific machines allowed to
send to these groups?

Dale

----------------------------------
Dale W. Carder - Network Engineer
University of Wisconsin at Madison
http://net.doit.wisc.edu/~dwcarder

_______________________________________________
firewall-wizards mailing list
firewall-wizards_at_listserv.icsalabs.com
https://listserv.icsalabs.com/mailman/listinfo/firewall-wizards
Received on Aug 02 2006

[ Nmap | Sec Tools | Mailing Lists | Site News | About/Contact | Advertising | Privacy ]
edgeos