nanog mailing list archives

Re: High throughput bgp links using gentoo + stipped kernel


From: Matt Palmer <mpalmer () hezmatt org>
Date: Tue, 21 May 2013 07:45:58 +1000

On Sun, May 19, 2013 at 04:42:23PM -0700, Seth Mattinen wrote:
On 5/19/13 4:27 PM, Ben wrote:
Do you actually need stateful filtering?  A lot of people seem to think
that it's important, when really they're accomplishing little from it,
you can block ports etc without it.

I believe PCI compliance requires it, other things like it probably do too.

There'd be very few PCI compliant sites if PCI required stateful firewalling
in core routers.

- Matt



Current thread: