Firewall Wizards mailing list archives

GXD vs. SPF


From: "Stout, Bill" <StoutB () pios com>
Date: Thu, 24 Sep 1998 20:28:54 -0400


Having done my fair share of hand waving and whiteboarding about AG vs. SPF,
I'm curious about something else.  

Generic Proxy security vs. SPF session security.

Given a specific traffic session, ignoring the whole packet-level attack
catagory: 
If the GXD simply reassembles segments to TCP windows and passes them on to
the target, only using sequence numbers to keep track of the TCP session,
would a SPF provide better validation of a session than a generic proxy?

The security stack would be:

AG
SPF
GXD
Packet Filter

Bill Stout



Current thread: