Full Disclosure mailing list archives

RE: PIX vs CheckPoint; IMHO Netscreen is far su perior


From: "Forbes, Robert" <Robert_Forbes () reyrey com>
Date: Tue, 29 Jun 2004 19:11:05 -0400


It really depends on the requirements one has for a firewall and which
Checkpoint platform they are going to run on, Nokia, SecPlat on a Dell,
Alteon, or CrossBeam. And if you are going to use vulnerabilities as a
reason you should then be using Secure Computing Sidewinder.


-----Original Message-----
From: Edward W. Ray [mailto:support () mmicman com] 
Sent: Tuesday, June 29, 2004 5:27 PM
To: full-disclosure () lists netsys com
Subject: RE: [Full-disclosure] PIX vs CheckPoint; IMHO Netscreen is far
superior

IMHO, neither is very good. 

I have been using Netscreen (bought by Juniper for $4 billion earlier this
year) products for over fours years.  PIX is a very buggy and exploitable
OS.  Checkpoint is somewhat better, although it dies under most DoS attacks.

My netscreen have been much better at shunting DoS attacks, have far less
vulnerabilities reported than either Checkpoint or PIX, and is a true
hardware firewall with its own custom ASIC.

If your choices are only checkpoint or PIX, I would choose Checkpoint.  IMHO
it is more reliable.  But if you really want a networking company that is
not a marketing company, check out Juniper/Netscreen Firewalls,
http://www.netscreen.com

Good luck with your studies!

Edward W. Ray 

-----Original Message-----
From: full-disclosure-admin () lists netsys com
[mailto:full-disclosure-admin () lists netsys com] On Behalf Of Eric Paynter
Sent: Tuesday, June 29, 2004 1:47 PM
To: full-disclosure () lists netsys com
Subject: RE: [Full-disclosure] PIX vs CheckPoint

On Tue, June 29, 2004 11:59 am, James Patterson Wicks said:
CheckPoint's interface is very intuitive and easy to use.

Easy to use in a "Microsoft" kind of way. Last I heard, it does nice things
for you like always allow DNS traffic through, even if you have no port 53
rule and a deny all policy. How helpful!

-Eric

--
arctic bears - affordable email and name services @yourdomain.com
http://www.arcticbears.com

_______________________________________________
Full-Disclosure - We believe in it.
Charter: http://lists.netsys.com/full-disclosure-charter.html

_______________________________________________
Full-Disclosure - We believe in it.
Charter: http://lists.netsys.com/full-disclosure-charter.html

_______________________________________________
Full-Disclosure - We believe in it.
Charter: http://lists.netsys.com/full-disclosure-charter.html


Current thread: