<?xml version="1.0" encoding="utf-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
  <channel>
    <title>Firewall Wizards</title>
    <link>http://seclists.org/#firewall-wizards</link>
    <atom:link href="http://seclists.org/rss/firewall-wizards.rss" rel="self" type="application/rss+xml" />
    <language>en-us</language>
    <description>Tips and tricks for firewall administrators</description>
    <pubDate>Tue, 17 Nov 2009 19:00:22 GMT</pubDate>
    <lastBuildDate>Tue, 17 Nov 2009 19:00:22 GMT</lastBuildDate>
<!-- MHonArc v2.6.16 -->

 

  <item>
    <title>Re: Message Labs</title>
    <link>http://seclists.org/firewall-wizards/2009/Nov/14</link>
    <description>&lt;p&gt;Posted by A on Nov 17&lt;/p&gt;Yeah, its if you are using their mail-filtering service, for them to&lt;br&gt;
be able to send you mail you have to allow the ip ranges.&lt;br&gt;
&lt;br&gt;
Most people will lock down the router to only accept email from the&lt;br&gt;
hosted security provider.. to reduce spam.&lt;br&gt;
&lt;br&gt;
Aaron&lt;br&gt;
&lt;br&gt;
\                                                                          /&lt;br&gt;
Putting the F in BOFH!&lt;br&gt;
&lt;br&gt;
2009/11/11 Brian Loe &amp;lt;knobdy () gmail com&amp;gt;:&lt;br&gt;</description>
    <pubDate>Tue, 17 Nov 2009 18:46:39 GMT</pubDate>
    <guid isPermaLink="true">http://seclists.org/firewall-wizards/2009/Nov/14</guid>
  </item>
  <item>
    <title>Re: port scanning activity going up recently?</title>
    <link>http://seclists.org/firewall-wizards/2009/Nov/13</link>
    <description>&lt;p&gt;Posted by Nate Itkin on Nov 17&lt;/p&gt;Overall illicit activity looks to be down slightly.&lt;br&gt;
see: &lt;a  rel=&quot;nofollow&quot; href=&quot;http://www.dshield.org/submissions.html&quot;&gt;http://www.dshield.org/submissions.html&lt;/a&gt;  (select sources, targets, &lt;br&gt;
and reports for 2009)&lt;br&gt;
&lt;br&gt;
Cheers,&lt;br&gt;
Nate Itkin&lt;br&gt;</description>
    <pubDate>Tue, 17 Nov 2009 18:45:35 GMT</pubDate>
    <guid isPermaLink="true">http://seclists.org/firewall-wizards/2009/Nov/13</guid>
  </item>
  <item>
    <title>Re: Message Labs</title>
    <link>http://seclists.org/firewall-wizards/2009/Nov/12</link>
    <description>&lt;p&gt;Posted by shane brennan on Nov 17&lt;/p&gt;Hi&lt;br&gt;
&lt;br&gt;
We use it in work. havent received any notification like that&lt;br&gt;
&lt;br&gt;
Shane&lt;br&gt;</description>
    <pubDate>Tue, 17 Nov 2009 18:44:18 GMT</pubDate>
    <guid isPermaLink="true">http://seclists.org/firewall-wizards/2009/Nov/12</guid>
  </item>


  <item>
    <title>Re: Network design change</title>
    <link>http://seclists.org/firewall-wizards/2009/Nov/11</link>
    <description>&lt;p&gt;Posted by sai on Nov 15&lt;/p&gt;not good  from a security point of view.&lt;br&gt;
&lt;br&gt;
I would prefer to connect the routers, at the internet cloud level not the&lt;br&gt;
DMZ level. I'd have the 2 core switches connected as you have.&lt;br&gt;
&lt;br&gt;
2 reasons:&lt;br&gt;
[1] gives me redundant internet connectivity in case one of the isps goes&lt;br&gt;
down (assuming multiple isps and routing that can handle one link going&lt;br&gt;
down)&lt;br&gt;
[2] the DMZs should be separate. the more segments you have the better.&lt;br&gt;
connecting the 2 at switch level...&lt;br&gt;</description>
    <pubDate>Sun, 15 Nov 2009 14:21:08 GMT</pubDate>
    <guid isPermaLink="true">http://seclists.org/firewall-wizards/2009/Nov/11</guid>
  </item>
  <item>
    <title>Re: Network design change</title>
    <link>http://seclists.org/firewall-wizards/2009/Nov/10</link>
    <description>&lt;p&gt;Posted by pkc_mls on Nov 15&lt;/p&gt;shadow floating a écrit :&lt;br&gt;
&lt;br&gt;
If it's possible, I'd rather use a link between both firewalls&lt;br&gt;
to connect the DMZ.&lt;br&gt;
&lt;br&gt;
If you connect directly the dmz switches, and if someone can get access&lt;br&gt;
to your dmz, he will get access to the other one as well, as there won't&lt;br&gt;
be any filtering between the DMZs.&lt;br&gt;
&lt;br&gt;
do the DMZ share the same network addresses ?&lt;br&gt;
&lt;br&gt;
if not, just use an unused interface on each fw, connect both via a&lt;br&gt;
link, then create some routes to allow...&lt;br&gt;</description>
    <pubDate>Sun, 15 Nov 2009 14:20:02 GMT</pubDate>
    <guid isPermaLink="true">http://seclists.org/firewall-wizards/2009/Nov/10</guid>
  </item>
  <item>
    <title>Re: secure firewall rule management program</title>
    <link>http://seclists.org/firewall-wizards/2009/Nov/9</link>
    <description>&lt;p&gt;Posted by Lan Li on Nov 15&lt;/p&gt;Athena Security also provides a cleanup tool/basic ops tool. Works with&lt;br&gt;
Cisco, Check Point and Netscreen firewalls. Available for eval download at&lt;br&gt;
&lt;a  rel=&quot;nofollow&quot; href=&quot;http://www.athenasecurity.net/firepac_trial.html&quot;&gt;http://www.athenasecurity.net/firepac_trial.html&lt;/a&gt;&lt;br&gt;
&lt;br&gt;
Lan Li&lt;br&gt;
&lt;br&gt;
-----Original Message-----&lt;br&gt;
&lt;br&gt;
From: firewall-wizards-bounces () listserv icsalabs com&lt;br&gt;
&lt;br&gt;
[&lt;a  rel=&quot;nofollow&quot; href=&quot;mailto:firewall-wizards-bounces&quot;&gt;mailto:firewall-wizards-bounces&lt;/a&gt; () listserv icsalabs com] On Behalf Of Marcin&lt;br&gt;
Antkiewicz&lt;br&gt;
&lt;br&gt;
Sent: Thursday, November 05, 2009 10:52 PM&lt;br&gt;
&lt;br&gt;
To: Firewall Wizards...&lt;br&gt;</description>
    <pubDate>Sun, 15 Nov 2009 14:18:47 GMT</pubDate>
    <guid isPermaLink="true">http://seclists.org/firewall-wizards/2009/Nov/9</guid>
  </item>
  <item>
    <title>Re: OT, sorta: Breaking pipes?</title>
    <link>http://seclists.org/firewall-wizards/2009/Nov/8</link>
    <description>&lt;p&gt;Posted by Kurt Buff on Nov 15&lt;/p&gt;We don't use perl/cgi here, but the example is instructive.&lt;br&gt;
&lt;br&gt;
This issue at hand is for web browsing by clients - the newish manager&lt;br&gt;
believes that it's just too annoying to add exceptions for the&lt;br&gt;
misbehaving web sites. Of course, it's not just the pipe character.&lt;br&gt;
It's also the other unsafe/unwise characters, and the URLs that are&lt;br&gt;
longer than 1024 characters, etc.&lt;br&gt;
&lt;br&gt;
At some point we may be hosting a web site locally, but that hasn't happened.&lt;br&gt;
&lt;br&gt;
This...&lt;br&gt;</description>
    <pubDate>Sun, 15 Nov 2009 14:17:37 GMT</pubDate>
    <guid isPermaLink="true">http://seclists.org/firewall-wizards/2009/Nov/8</guid>
  </item>
  <item>
    <title>Message Labs</title>
    <link>http://seclists.org/firewall-wizards/2009/Nov/7</link>
    <description>&lt;p&gt;Posted by Brian Loe on Nov 15&lt;/p&gt;Anyone here using message labs? Have you received notice that you MUST&lt;br&gt;
open up your firewall for 8 or so networks?&lt;br&gt;</description>
    <pubDate>Sun, 15 Nov 2009 14:16:28 GMT</pubDate>
    <guid isPermaLink="true">http://seclists.org/firewall-wizards/2009/Nov/7</guid>
  </item>
  <item>
    <title>port scanning activity going up recently?</title>
    <link>http://seclists.org/firewall-wizards/2009/Nov/6</link>
    <description>&lt;p&gt;Posted by Ken Fox on Nov 15&lt;/p&gt;Hi all -&lt;br&gt;
&lt;br&gt;
        Has anyone else noticed a recent spike in port scan activity over the last&lt;br&gt;
few days?&lt;br&gt;
&lt;br&gt;
        I've been seeing some interesting traffic where multiple source addresses&lt;br&gt;
are probing a number of the same high order destination ports from a small&lt;br&gt;
set of source ports with a number of different but specific packet sizes.&lt;br&gt;
&lt;br&gt;
        e.g.: source port 3268 -&amp;gt; dest port 50572 packet size 48, 60, 64, and 52&lt;br&gt;
        egg: source port 3268...&lt;br&gt;</description>
    <pubDate>Sun, 15 Nov 2009 14:15:09 GMT</pubDate>
    <guid isPermaLink="true">http://seclists.org/firewall-wizards/2009/Nov/6</guid>
  </item>


  <item>
    <title>Re: Network design change</title>
    <link>http://seclists.org/firewall-wizards/2009/Nov/5</link>
    <description>&lt;p&gt;Posted by shadow floating on Nov 10&lt;/p&gt; Hi All,&lt;br&gt;
 My company has two sites in to 2 different locations that are&lt;br&gt;
 connected via high speed link at the core layer ( I've attached a&lt;br&gt;
 link to the diagram :&lt;br&gt;
&lt;a  rel=&quot;nofollow&quot; href=&quot;http://img18.imageshack.us/img18/77/questionhk.jpg&quot;&gt;http://img18.imageshack.us/img18/77/questionhk.jpg&lt;/a&gt; for ease of&lt;br&gt;
explanation)&lt;br&gt;
 in each site I've 1 DMZ , the network team wants to connect the DMZ&lt;br&gt;
 switches in both sites for better performance and &amp;quot;security&amp;quot; - the&lt;br&gt;
 link under investigation is shown in red in the picture -   via...&lt;br&gt;</description>
    <pubDate>Tue, 10 Nov 2009 19:56:57 GMT</pubDate>
    <guid isPermaLink="true">http://seclists.org/firewall-wizards/2009/Nov/5</guid>
  </item>
  <item>
    <title>Re: secure firewall rule management program</title>
    <link>http://seclists.org/firewall-wizards/2009/Nov/4</link>
    <description>&lt;p&gt;Posted by Marcin Antkiewicz on Nov 10&lt;/p&gt;Hi Morty,&lt;br&gt;
&lt;br&gt;
we are looking at the same, but we are looking for a cleanup/basic ops support&lt;br&gt;
tool right now.&lt;br&gt;
&lt;br&gt;
Would you mind sharing the dealbreaking requirements? I am wondering now&lt;br&gt;
what, if anything we have missed.&lt;br&gt;</description>
    <pubDate>Tue, 10 Nov 2009 19:55:39 GMT</pubDate>
    <guid isPermaLink="true">http://seclists.org/firewall-wizards/2009/Nov/4</guid>
  </item>
  <item>
    <title>Re: OT, sorta: Breaking pipes?</title>
    <link>http://seclists.org/firewall-wizards/2009/Nov/3</link>
    <description>&lt;p&gt;Posted by Chris Myers on Nov 10&lt;/p&gt;Do you use Perl at all with CGI scripts? If so, this is just an  &lt;br&gt;
example of what might be done with anything written with custom  &lt;br&gt;
scripts. In this case, it is a specific vendor, but it could happen to  &lt;br&gt;
anyone who does not code diligently.&lt;br&gt;
&lt;br&gt;
&lt;a  rel=&quot;nofollow&quot; href=&quot;http://www.kb.cert.org/vuls/id/496064&quot;&gt;http://www.kb.cert.org/vuls/id/496064&lt;/a&gt;&lt;br&gt;
&lt;br&gt;
Thank You,&lt;br&gt;
&lt;br&gt;
Chris Myers&lt;br&gt;
clmmacunix () charter net&lt;br&gt;
&lt;br&gt;
John 1:17&lt;br&gt;
For the Law was given through Moses; grace and truth were realized  &lt;br&gt;
through Jesus Christ.&lt;br&gt;
&lt;br&gt;
    Go Vols!!!!&lt;br&gt;</description>
    <pubDate>Tue, 10 Nov 2009 19:54:07 GMT</pubDate>
    <guid isPermaLink="true">http://seclists.org/firewall-wizards/2009/Nov/3</guid>
  </item>


  <item>
    <title>Re: secure firewall rule management program</title>
    <link>http://seclists.org/firewall-wizards/2009/Nov/2</link>
    <description>&lt;p&gt;Posted by Morty Abzug on Nov 05&lt;/p&gt;Thanks!  We're looking both at Tufin (mentioned by Rainer Ginsberg)&lt;br&gt;
and at Algosec (mentioned by one of our managers and by Rainer).  The&lt;br&gt;
current versions of both products fail to meet several of our&lt;br&gt;
dealbreaking requirements.  Both products are relatively new.  We're&lt;br&gt;
hopeful that a future version of one or both products will be what we&lt;br&gt;
want.&lt;br&gt;
&lt;br&gt;
- Morty&lt;br&gt;</description>
    <pubDate>Thu, 05 Nov 2009 22:57:53 GMT</pubDate>
    <guid isPermaLink="true">http://seclists.org/firewall-wizards/2009/Nov/2</guid>
  </item>
  <item>
    <title>Re: secure firewall rule management program</title>
    <link>http://seclists.org/firewall-wizards/2009/Nov/1</link>
    <description>&lt;p&gt;Posted by Matthias Leu on Nov 05&lt;/p&gt;Hi Morty,&lt;br&gt;
have you had a look at Tufin SecureTrack and SecureChange Workflow?&lt;br&gt;
It's not free, but quite good and I think your requirements are fulfilled.&lt;br&gt;
&lt;br&gt;
It runs on Linux and is written by security professionals.&lt;br&gt;
SecureTrack is connected to Check Point SmartCenter or MDS/CMA via&lt;br&gt;
OPSEC, other vendors are supported too (e.g. Juniper, Cisco,&lt;br&gt;
Fortinet,...).&lt;br&gt;
Each 'save' gives a new revision, no 'install' necessary. So reports,&lt;br&gt;
and above all, alerts...&lt;br&gt;</description>
    <pubDate>Thu, 05 Nov 2009 22:56:50 GMT</pubDate>
    <guid isPermaLink="true">http://seclists.org/firewall-wizards/2009/Nov/1</guid>
  </item>
  <item>
    <title>OT, sorta: Breaking pipes?</title>
    <link>http://seclists.org/firewall-wizards/2009/Nov/0</link>
    <description>&lt;p&gt;Posted by Kurt Buff on Nov 05&lt;/p&gt;All,&lt;br&gt;
&lt;br&gt;
At $WORK I admin a nice Sidewinder. Works well. I like it, though I'm&lt;br&gt;
not as fully trained on it as I'd like to be.&lt;br&gt;
&lt;br&gt;
However, I'm seeing more complaints from end-users who are&lt;br&gt;
encountering web sites that issue URLs with the pipe/vertical bar -&lt;br&gt;
&amp;quot;|&amp;quot; - character embedded in them. The Sidewinder proxy denies it, as&lt;br&gt;
is proper. The latest occurrence is a really stupid State government&lt;br&gt;
web site that actually puts the pipe character at...&lt;br&gt;</description>
    <pubDate>Thu, 05 Nov 2009 22:55:33 GMT</pubDate>
    <guid isPermaLink="true">http://seclists.org/firewall-wizards/2009/Nov/0</guid>
  </item>

 

<!-- MHonArc v2.6.16 -->
  </channel>
</rss>
