Security Basics mailing list archives

RE: Cisco PIX fixup protocol command


From: "Stefan Greve" <Stefan.Greve () rnw nl>
Date: Thu, 12 Feb 2004 06:59:07 -0000

Hi,

Maybe this URL will help you with this question.

http://www.cisco.com/en/US/products/sw/secursw/ps2120/products_configuration_guide_chapter09186a008017278b.html

Best regards,
Radio Netherlands.


Stefan Greve.

-----------

Radio Netherlands, the dutch international service







-----Original Message-----
From: S.Rohit [mailto:s.rohit () usa net]
Sent: woensdag 11 februari 2004 11:53
To: security-basics () securityfocus com
Subject: Cisco PIX fixup protocol command


hi everyone....

   might sound like a very stupid question to ask, but i am looking for info
on wat is the use of fixup protocol commands on the Cisco PIX device. wat is
the exact usage and significance of this commands? and wat are the security
implications of this command? i know that some fixup's like say fixup protocol
smtp are good cos of the way they restrict the SMTP command set but how about
the general syntax [no] fixup protocol [service] [port]? what is this used for
and wat are the security implications for this?

   i am asking this because i'm seeing a recommendation in some PIX hardening
guide to disable fixups or they flag fixups as a security issue? y is tat? 

rohit



---------------------------------------------------------------------------
Free trial: Astaro Security Linux -- firewall with Spam/Virus Protection

Protect your network with the comprehensive security solution that
integrates six applications for ease of use and lower TCO.

Firewall - Virus protection - Spam protection - URL blocking - VPN
- Wireless security.

Download 30-day evaluation at:
http://www.astaro.com/php/contact/securityfocus.php
----------------------------------------------------------------------------



De inhoud van deze e-mail, en eventuele bijlagen, is vertrouwelijk en uitsluitend bestemd voor de geadresseerde. 
Kennisneming en gebruik van de inhoud ervan door anderen zonder toestemming van de afzender of geadresseerde is 
onrechtmatig. Mocht dit e-mail bericht ten onrechte bij u terechtgekomen zijn, dan verzoeken wij u vriendelijk de 
e-mail uit uw systeem te verwijderen en direct contact met ons op te nemen.

Tenzij anders vermeld, is de inhoud van deze e-mail niet noodzakelijkerwijs de mening van Radio Nederland Wereldomroep.

This e-mail, and any attachment, is confidential. Unless specifically stated, the contents of this message may contain 
personal views which are not necessarily the views of Radio Netherlands.

If you have received this message in error, please delete it from your system, do not use or disclose the information 
by any means and notify me immediately.

---------------------------------------------------------------------------
Free trial: Astaro Security Linux -- firewall with Spam/Virus Protection

Protect your network with the comprehensive security solution that
integrates six applications for ease of use and lower TCO.

Firewall - Virus protection - Spam protection - URL blocking - VPN
- Wireless security.

Download 30-day evaluation at:
http://www.astaro.com/php/contact/securityfocus.php
----------------------------------------------------------------------------


Current thread: