Firewall Wizards mailing list archives

Re: What is the difference between stateful packet filtering and Stateful pkt inspection ?


From: Andrew Boodle <andrew.boodle () adacel com>
Date: Mon, 03 Feb 2003 08:59:16 +1100

Apart from the security aspects, the V Series products are still very new to Watchguard. While I think, as an almost mature product the Vseries are acceptable in the right circumstances.I my experience they are let down by a lack of V series expertise in the support area. Let me say I think this is a WG management issue as I feel that WG management have not ensured the support staff have enough experience with dealing with some of the more technical areas of the Vseries. WG management need to ensure their staff are as expert on the V Series as they are on the other (more mature) WG Products.

In my experience, the V series:
are easier to manage than the FB 1000's
they have much greater throughput,
I have found them on the whole to be much more stable.
take up less space in the rack,
slightly easier to setup.


Have you considered what the future holds for your situation
increased throughput?
Extended technical requirements (ie Vlans)?
Need for high availability?
VPN
etc...

If you expect your needs to grow significantly perhaps consider the V Series.

Good luck

AB



anil bindal wrote:

Hi,

1) What is the difference between a stateful pkt filter and stateful
packet inspection ?
2) Does any of above two include the payload verificaion and analysis (
i.e. application level Proxies !)?
3) What does the WG FB 1000 do ? Stateful Pkt Inspection or Stateful Pkt
filtering ?
4) What does the WG V60 do ? SPInspection or SPfiltering ?
5) Does the Watch Guard http-filter rule does the same processing on the
packet as the check point or CISCO PIX rule ??
6) Lastly is the stateful packet ( filter or inspection whatever the WG
boxes do )  sufficient from the security point of view ( no application
level proxies ? )

why all above questions are being asked is bcose i want to decide on
either FB 1000 or V60. One of them has BW management and other does not
have the application level proxies ??

What level of security will i compromise if i decide on V60 with BW
management ??

thanks and regards
anil bindal





_______________________________________________
firewall-wizards mailing list
firewall-wizards () honor icsalabs com
http://honor.icsalabs.com/mailman/listinfo/firewall-wizards


Current thread: