Nmap Security Scanner
*Intro
*Ref Guide
*Install Guide
*Download
*Changelog
*Book
*Docs
Security Lists
*Nmap Hackers
*Nmap Dev
*Bugtraq
*Full Disclosure
*Pen Test
*Basics
*More
Security Tools
*Pass crackers
*Sniffers
*Vuln Scanners
*Web scanners
*Wireless
*Exploitation
*Packet crafters
*More
Site News
Site Search:
Exploit World
Advertising
About/Contact
Credits
Sponsors:
edgeos



Firewall Wizards: Re: How automate firewall tests

Re: How automate firewall tests

From: haim [howard] roman <roman_at_jct.ac.il>
Date: Wed, 23 Aug 2006 18:32:10 +0300

-------- Original Message --------
From: jseymour_at_linxnet.com (Jim Seymour)
To: firewall-wizards_at_listserv.cybertrust.com
Subject: Re:[fw-wiz] How automate firewall tests
Date: Wed Aug 23 17:49:46 2006

> "R. DuFresne" <dufresne_at_sysinfo.com> wrote:
>
>> On Fri, 18 Aug 2006, Keith A. Glass wrote:
>>
> [snip]
>
>>> Well. . .we packet-filter at the border routers and switches prior to the
>>> border firewall to take some of the load off. . .but then ALL our routers
>>> are
>>> set to packet filter as an additional security measure. . .
>>>
>>>
>>>
>> It might amaze a number of folks to learn how uncommon this setup is these
>> days.
>>
> [snip]
>
> In a way it amazes me, and in a way it does not. It amazes me in that
> it's such a logical thing to do, I'm at a loss as to understand why
> somebody wouldn't. (I'm speaking in general terms. I'm sure there are
> perfectly valid exceptions.) It does not amaze me in that I've come to
> the conclusion that competence is (increasingly) a rare thing.
>
> The router needs to protect itself. The router can also aid in the
> protection of the firewall. The router can also take some of the load
> off the firewall.
>
>

Like everything else, you have to plan this well. If you end up with
too many redundant rules on different network equipment, you give
yourself a management headache.

~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Haim (Howard) Roman
Computer Center, Jerusalem College of Technology
roman_at_jct.ac.il

_______________________________________________
firewall-wizards mailing list
firewall-wizards_at_listserv.icsalabs.com
https://listserv.icsalabs.com/mailman/listinfo/firewall-wizards
Received on Aug 23 2006

[ Nmap | Sec Tools | Mailing Lists | Site News | About/Contact | Advertising | Privacy ]
edgeos