Firewall Wizards mailing list archives
RE: Firewall comparison in Data Communications
From: W J La Cholter <tck () giage com>
Date: Wed, 2 Jun 1999 09:54:43 -0400
I know Gauntlet 1.1 for Windows NT, which came out in July 1997, blocked source-routed traffic. It was the first version with kernel-level changes for filtering and transparency. We implemented the same algorithms for screening packets as Gauntlet 3 for UNIX. Most NT firewalls that have a kernel-mode driver should be able to screen source-routed packets and other nasties. - W. J. La Cholter <blacholter () giage com> - Giage PGP 5 Fingerprint: 79E0 EE3A 2EC1 2303 624C AE99 F31B 972B F24F 688E -----Original Message----- From: Matt Curtin [mailto:cmcurtin () interhack net] Sent: Monday, May 24, 1999 10:22 PM To: David Newman Cc: firewall-wizards () nfr net; firewalls () lists gnac net Subject: Re: Firewall comparison in Data Communications Hmm. I saw no mention of attempts to source-route traffic. I have been told that NT doesn't have the ability to detect and block source-routed packets. Are NT firewalls somehow detecting and dropping these things these days? Or is it true that NT firewalls are unable to block this attack without help from another component with half a brain (i.e., having the access router drop source routed stuff)? -- Matt Curtin cmcurtin () interhack net http://www.interhack.net/people/cmcurtin/ - [To unsubscribe, send mail to majordomo () lists gnac net with "unsubscribe firewalls" in the body of the message.]
Current thread:
- Re: Firewall comparison in Data Communications Matt Curtin (Jun 01)
- <Possible follow-ups>
- RE: Firewall comparison in Data Communications Brian Steele (Jun 01)
- RE: Firewall comparison in Data Communications Ray Hooker (Jun 02)
- RE: Firewall comparison in Data Communications David T. Smith (Jun 03)
- RE: Firewall comparison in Data Communications Alexander Schreiber (Jun 03)
- Re: Firewall comparison in Data Communications Chris Brenton (Jun 03)
- Re: Firewall comparison in Data Communications Ge' Weijers (Jun 02)
- RE: Firewall comparison in Data Communications David Newman (Jun 02)
- RE: Firewall comparison in Data Communications Kevin Steves (Jun 14)
- RE: Firewall comparison in Data Communications W J La Cholter (Jun 03)
- Re: Firewall comparison in Data Communications Don Kendrick (Jun 03)
- RE: Firewall comparison in Data Communications Russ (Jun 03)
- RE: Firewall comparison in Data Communications csingletary (Jun 03)
- RE: Firewall comparison in Data Communications Rob Polansky (Jun 04)
- Re: Firewall comparison in Data Communications Steven M. Bellovin (Jun 03)
- Re: Firewall comparison in Data Communications Ge' Weijers (Jun 03)
- Re: Firewall comparison in Data Communications dnewman (Jun 03)
- Re: Firewall comparison in Data Communications Ge' Weijers (Jun 03)
- Re: Firewall comparison in Data Communications Kevin Steves (Jun 14)
- RE: Firewall comparison in Data Communications Robert Graham (Jun 03)