<?xml version="1.0" encoding="utf-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
  <channel>
    <title>Firewall Wizards</title>
    <link>http://seclists.org/#firewall-wizards</link>
    <atom:link href="http://seclists.org/rss/firewall-wizards.rss" rel="self" type="application/rss+xml" />
    <language>en-us</language>
    <description>Tips and tricks for firewall administrators</description>
    <pubDate>Thu, 05 Nov 2009 23:00:08 GMT</pubDate>
    <lastBuildDate>Thu, 05 Nov 2009 23:00:08 GMT</lastBuildDate>
<!-- MHonArc v2.6.16 -->

 

  <item>
    <title>Re: secure firewall rule management program</title>
    <link>http://seclists.org/firewall-wizards/2009/Nov/2</link>
    <description>&lt;p&gt;Posted by Morty Abzug on Nov 05&lt;/p&gt;Thanks!  We're looking both at Tufin (mentioned by Rainer Ginsberg)&lt;br&gt;
and at Algosec (mentioned by one of our managers and by Rainer).  The&lt;br&gt;
current versions of both products fail to meet several of our&lt;br&gt;
dealbreaking requirements.  Both products are relatively new.  We're&lt;br&gt;
hopeful that a future version of one or both products will be what we&lt;br&gt;
want.&lt;br&gt;
&lt;br&gt;
- Morty&lt;br&gt;</description>
    <pubDate>Thu, 05 Nov 2009 22:57:53 GMT</pubDate>
    <guid isPermaLink="true">http://seclists.org/firewall-wizards/2009/Nov/2</guid>
  </item>
  <item>
    <title>Re: secure firewall rule management program</title>
    <link>http://seclists.org/firewall-wizards/2009/Nov/1</link>
    <description>&lt;p&gt;Posted by Matthias Leu on Nov 05&lt;/p&gt;Hi Morty,&lt;br&gt;
have you had a look at Tufin SecureTrack and SecureChange Workflow?&lt;br&gt;
It's not free, but quite good and I think your requirements are fulfilled.&lt;br&gt;
&lt;br&gt;
It runs on Linux and is written by security professionals.&lt;br&gt;
SecureTrack is connected to Check Point SmartCenter or MDS/CMA via&lt;br&gt;
OPSEC, other vendors are supported too (e.g. Juniper, Cisco,&lt;br&gt;
Fortinet,...).&lt;br&gt;
Each 'save' gives a new revision, no 'install' necessary. So reports,&lt;br&gt;
and above all, alerts...&lt;br&gt;</description>
    <pubDate>Thu, 05 Nov 2009 22:56:50 GMT</pubDate>
    <guid isPermaLink="true">http://seclists.org/firewall-wizards/2009/Nov/1</guid>
  </item>
  <item>
    <title>OT, sorta: Breaking pipes?</title>
    <link>http://seclists.org/firewall-wizards/2009/Nov/0</link>
    <description>&lt;p&gt;Posted by Kurt Buff on Nov 05&lt;/p&gt;All,&lt;br&gt;
&lt;br&gt;
At $WORK I admin a nice Sidewinder. Works well. I like it, though I'm&lt;br&gt;
not as fully trained on it as I'd like to be.&lt;br&gt;
&lt;br&gt;
However, I'm seeing more complaints from end-users who are&lt;br&gt;
encountering web sites that issue URLs with the pipe/vertical bar -&lt;br&gt;
&amp;quot;|&amp;quot; - character embedded in them. The Sidewinder proxy denies it, as&lt;br&gt;
is proper. The latest occurrence is a really stupid State government&lt;br&gt;
web site that actually puts the pipe character at...&lt;br&gt;</description>
    <pubDate>Thu, 05 Nov 2009 22:55:33 GMT</pubDate>
    <guid isPermaLink="true">http://seclists.org/firewall-wizards/2009/Nov/0</guid>
  </item>

 

<!-- MHonArc v2.6.16 -->
<!-- MHonArc v2.6.16 -->

 

  <item>
    <title>Re: secure firewall rule management program</title>
    <link>http://seclists.org/firewall-wizards/2009/Oct/23</link>
    <description>&lt;p&gt;Posted by Avishai Wool on Oct 25&lt;/p&gt;Mordechai,&lt;br&gt;
&lt;br&gt;
AlgoSec FireFlow does pretty much exactly what you need.&lt;br&gt;
It is definitely topology aware and can tell you which firewalls&lt;br&gt;
you should modify to meet a change request.&lt;br&gt;
It has rule expiration built in.&lt;br&gt;
Supports Check Point, Cisco, Juniper, Fortinet.&lt;br&gt;
&lt;br&gt;
&lt;a  rel=&quot;nofollow&quot; href=&quot;http://www.algosec.com&quot;&gt;http://www.algosec.com&lt;/a&gt;&lt;br&gt;
&lt;br&gt;
Avishai&lt;br&gt;
&lt;br&gt;
disclaimer: I'm AlgoSec CTO &amp;amp; Co-Founder so I'm biased.&lt;br&gt;</description>
    <pubDate>Sun, 25 Oct 2009 22:10:43 GMT</pubDate>
    <guid isPermaLink="true">http://seclists.org/firewall-wizards/2009/Oct/23</guid>
  </item>


  <item>
    <title>Re: Palo Alto Networks</title>
    <link>http://seclists.org/firewall-wizards/2009/Oct/22</link>
    <description>&lt;p&gt;Posted by Cassell, Damon Z. on Oct 14&lt;/p&gt;Palo Alto does have central management by using an additional product called Panorama.&lt;br&gt;
&lt;br&gt;
&lt;a  rel=&quot;nofollow&quot; href=&quot;http://www.paloaltonetworks.com/products/panorama.html&quot;&gt;http://www.paloaltonetworks.com/products/panorama.html&lt;/a&gt;&lt;br&gt;
&lt;br&gt;
One observation on the topic of management; the Palo Alto logging scheme seemed clunky, especially with a lot of &lt;br&gt;
logging enabled. If you are a frequent user of, say, Check Point SmartView Tracker then you might be annoyed with a &lt;br&gt;
web-based viewer and have some trouble with the query capabilities. Maybe...&lt;br&gt;</description>
    <pubDate>Wed, 14 Oct 2009 13:46:38 GMT</pubDate>
    <guid isPermaLink="true">http://seclists.org/firewall-wizards/2009/Oct/22</guid>
  </item>


  <item>
    <title>Re: Palo Alto Networks</title>
    <link>http://seclists.org/firewall-wizards/2009/Oct/21</link>
    <description>&lt;p&gt;Posted by Paul Hutchings on Oct 13&lt;/p&gt;Thanks all.&lt;br&gt;
&lt;br&gt;
Frank, We would only be looking at one unit so management shouldn't  &lt;br&gt;
be an issue.  You mentioned &amp;quot;home grown apps&amp;quot; and giving them a  &lt;br&gt;
definition, this will hopefully all be clear once I have a units GUI  &lt;br&gt;
in front of me, but presumably if you need/want it to the PA boxes  &lt;br&gt;
can also act as dumb stateful firewalls i.e. &amp;quot;Simply allow port XYZ  &lt;br&gt;
from X to Y&amp;quot;?&lt;br&gt;
&lt;br&gt;
Arkanoid, I've learned not to trust the marketing hence...&lt;br&gt;</description>
    <pubDate>Tue, 13 Oct 2009 21:49:39 GMT</pubDate>
    <guid isPermaLink="true">http://seclists.org/firewall-wizards/2009/Oct/21</guid>
  </item>
  <item>
    <title>Re: Slow FTP transfers</title>
    <link>http://seclists.org/firewall-wizards/2009/Oct/20</link>
    <description>&lt;p&gt;Posted by sky on Oct 13&lt;/p&gt;Hi Chris,&lt;br&gt;
&lt;br&gt;
There are no tracking module(s) that I know of. These servers are&lt;br&gt;
located behind FWSM.&lt;br&gt;
&lt;br&gt;
I haven't tried different server but active mode seems to cause&lt;br&gt;
intermittent problem whereas passive mode seems to be the work around.&lt;br&gt;
&lt;br&gt;
regards,&lt;br&gt;
sky&lt;br&gt;
&lt;br&gt;
Chris Smith wrote:&lt;br&gt;</description>
    <pubDate>Tue, 13 Oct 2009 21:48:18 GMT</pubDate>
    <guid isPermaLink="true">http://seclists.org/firewall-wizards/2009/Oct/20</guid>
  </item>


  <item>
    <title>Re: Palo Alto Networks</title>
    <link>http://seclists.org/firewall-wizards/2009/Oct/19</link>
    <description>&lt;p&gt;Posted by ArkanoiD on Oct 09&lt;/p&gt;Ah, and it does SSL MITM as well. I do not have any hands-on experience, though.&lt;br&gt;
&lt;br&gt;
(going to publish a whitepaper on &amp;quot;benevolent&amp;quot; SSL MITM proxy soon which fixes several&lt;br&gt;
SSL security problems ;-)&lt;br&gt;</description>
    <pubDate>Fri, 09 Oct 2009 13:54:15 GMT</pubDate>
    <guid isPermaLink="true">http://seclists.org/firewall-wizards/2009/Oct/19</guid>
  </item>
  <item>
    <title>Re: Palo Alto Networks</title>
    <link>http://seclists.org/firewall-wizards/2009/Oct/18</link>
    <description>&lt;p&gt;Posted by ArkanoiD on Oct 09&lt;/p&gt;The idea itself is quite good for some cases (do not rely on port numbers, use&lt;br&gt;
traffic signatures *instead*). Though it sounds much as &amp;quot;giving up application control&amp;quot; ;-)&lt;br&gt;
&lt;br&gt;
The marketing bullshit is awful, though. There is a dozen whitepapers with amazingly little&lt;br&gt;
useful technology details but too many buzzwords about &amp;quot;next generation&amp;quot;.&lt;br&gt;
&lt;br&gt;
Despite that, it seems to be quite decent product with (still DPI-driven) L7 inspection,...&lt;br&gt;</description>
    <pubDate>Fri, 09 Oct 2009 13:52:46 GMT</pubDate>
    <guid isPermaLink="true">http://seclists.org/firewall-wizards/2009/Oct/18</guid>
  </item>
  <item>
    <title>Re: Palo Alto Networks</title>
    <link>http://seclists.org/firewall-wizards/2009/Oct/17</link>
    <description>&lt;p&gt;Posted by Paul Hutchings on Oct 09&lt;/p&gt;Fair question.  At present we have an application aware firewall,  &lt;br&gt;
technically it is a proxy but it doesn't cache/we have no need to  &lt;br&gt;
cache.  Of course whilst it's smart enough to know whether what's  &lt;br&gt;
passing through it is valid/rfc compliant http/ftp/https and so on,  &lt;br&gt;
it has no idea if it's Skype, MSN Messenger, Webex and so on.  That's  &lt;br&gt;
the key area that I'm interested in, combined with the integrated  &lt;br&gt;
spyware/malware/virus filtering.&lt;br&gt;
&lt;br&gt;
As...&lt;br&gt;</description>
    <pubDate>Fri, 09 Oct 2009 13:51:30 GMT</pubDate>
    <guid isPermaLink="true">http://seclists.org/firewall-wizards/2009/Oct/17</guid>
  </item>
  <item>
    <title>Re: Palo Alto Networks</title>
    <link>http://seclists.org/firewall-wizards/2009/Oct/16</link>
    <description>&lt;p&gt;Posted by Francois Yang on Oct 09&lt;/p&gt;I've worked with them before and they're pretty good.&lt;br&gt;
easy setup and maintenance, good integration with Active Directory,&lt;br&gt;
good application detection engine.&lt;br&gt;
Over all it's a good product, but you have to test it in your own&lt;br&gt;
environment to see if it fits.&lt;br&gt;
here are the draw backs that I can remember. all firewalls have some&lt;br&gt;
kind of issues.&lt;br&gt;
here are the issues I see and maybe they have been fixed by now. I&lt;br&gt;
don't know it's been a while.&lt;br&gt;
I remember it...&lt;br&gt;</description>
    <pubDate>Fri, 09 Oct 2009 13:50:17 GMT</pubDate>
    <guid isPermaLink="true">http://seclists.org/firewall-wizards/2009/Oct/16</guid>
  </item>


  <item>
    <title>Palo Alto Networks</title>
    <link>http://seclists.org/firewall-wizards/2009/Oct/15</link>
    <description>&lt;p&gt;Posted by Paul Hutchings on Oct 08&lt;/p&gt;Getting one of their boxes on eval for a couple of weeks.  Quite a  &lt;br&gt;
broad and generic question I know, but does anyone have any experience &lt;br&gt;
(s) they wish to share?&lt;br&gt;
&lt;br&gt;
Cheers,&lt;br&gt;
Paul&lt;br&gt;</description>
    <pubDate>Thu, 08 Oct 2009 18:17:45 GMT</pubDate>
    <guid isPermaLink="true">http://seclists.org/firewall-wizards/2009/Oct/15</guid>
  </item>
  <item>
    <title>Re: asa 5505 vpn ipsec l2l problem</title>
    <link>http://seclists.org/firewall-wizards/2009/Oct/14</link>
    <description>&lt;p&gt;Posted by craig . wilson on Oct 08&lt;/p&gt;If you have tunnel interfaces setup on each end can you ping those addresses?  They should work even if your not &lt;br&gt;
passing anything into the tunnel.&lt;br&gt;
&lt;br&gt;
Sent from my BlackBerry® wireless device&lt;br&gt;
&lt;br&gt;
-----Original Message-----&lt;br&gt;
From: Eric Gearhart &amp;lt;eric () nixwizard net&amp;gt;&lt;br&gt;
Date: Mon, 5 Oct 2009 21:45:33 &lt;br&gt;
To: Firewall Wizards Security Mailing List&amp;lt;firewall-wizards () listserv icsalabs com&amp;gt;&lt;br&gt;
Subject: Re: [fw-wiz] asa 5505 vpn ipsec l2l problem&lt;br&gt;</description>
    <pubDate>Thu, 08 Oct 2009 18:16:33 GMT</pubDate>
    <guid isPermaLink="true">http://seclists.org/firewall-wizards/2009/Oct/14</guid>
  </item>
  <item>
    <title>Re: asa 5505 vpn ipsec l2l problem</title>
    <link>http://seclists.org/firewall-wizards/2009/Oct/13</link>
    <description>&lt;p&gt;Posted by Farrukh Haroon on Oct 08&lt;/p&gt;I don't know if you got my older email, here it is again:&lt;br&gt;
&lt;br&gt;
Run these three debugs&lt;br&gt;
debug crypto engine&lt;br&gt;
debug crypto isakmp 127&lt;br&gt;
debug crypto ipsec 127&lt;br&gt;
and then see if you get any more meaningful debugs.&lt;br&gt;
&lt;br&gt;
Its better to clear both Phase 1 and Phase 2 before you run the debugs (just&lt;br&gt;
in case the SAs are already established).&lt;br&gt;
&lt;br&gt;
Also try removing the crypto map from the interface and re-applying it!&lt;br&gt;
&lt;br&gt;
Please also check the logging levels on your ASA 'show...&lt;br&gt;</description>
    <pubDate>Thu, 08 Oct 2009 17:00:52 GMT</pubDate>
    <guid isPermaLink="true">http://seclists.org/firewall-wizards/2009/Oct/13</guid>
  </item>
  <item>
    <title>Re: asa 5505 vpn ipsec l2l problem</title>
    <link>http://seclists.org/firewall-wizards/2009/Oct/12</link>
    <description>&lt;p&gt;Posted by Eric Gearhart on Oct 08&lt;/p&gt;I think this was previously mentioned by Paul Melson... try to use IP&lt;br&gt;
addresses in your IPsec interesting traffic ACL... I agree with him, that&lt;br&gt;
having specific ports in ACL1 is the problem, as far as I know&lt;br&gt;
&lt;br&gt;
So ACL1 is now:&lt;br&gt;
access-list ACL1 extended permit tcp host 192.168.11.11 host 10.1.100.13 eq&lt;br&gt;
4000&lt;br&gt;
access-list ACL1 extended permit tcp host 192.168.11.11 host 10.1.110.250 eq&lt;br&gt;
4000&lt;br&gt;
access-list ACL1 extended permit tcp host 192.168.11.11 eq ftp...&lt;br&gt;</description>
    <pubDate>Thu, 08 Oct 2009 16:59:26 GMT</pubDate>
    <guid isPermaLink="true">http://seclists.org/firewall-wizards/2009/Oct/12</guid>
  </item>

 

<!-- MHonArc v2.6.16 -->
  </channel>
</rss>
