Firewall Wizards mailing list archives

RE: Firewall comparison in Data Communications


From: David Newman <dnewman () data com>
Date: Wed, 02 Jun 1999 18:17:19 -0400

<newbie-mode>What's a "source-routed packet"?  And what danger does it pose
to a Firewall?</newbie-mode>


TCP/IP has an facility that allows a packet to specify an explicit route
to a destination instead of going through the usual route lookup
process. The destination host must use the same path, which means a Bad
Guy can easily pose as a trusted host. This is a Terrible Idea from a
security standpoint. 

This is not to be confused with layer-2 source route bridging, which is
an Even Worse Idea ;-)

dn



Current thread: