Firewall Wizards mailing list archives
Re: How automate firewall tests
From: "Marcus J. Ranum" <mjr () ranum com>
Date: Mon, 21 Aug 2006 09:30:49 -0400
Patrick M. Hausen wrote:
Blocking ICMP completely breaks PMTUD.
Oh, THAT again. You've got it backwards. PMTUD is already broken; blocking ICMP simply makes that breakage apparent. When standards bodies deliberately standardize feature-sets that they are informed in advance are going to cause security problems, this is what you get. There was a time when a lot of the "internet pioneers" felt that firewalls were "evil" and that security interfered with the correct operation of the Internet ("information must be free!") That agenda resulted in some weird collisions with objective reality. I recall a time when lots of "internet pioneers" would go around saying stuff like "When IPV6 is here and nobody needs firewalls anymore.." or "Router ACLs are good enough." etc. And people wonder why the Internet protocol stack looks like it was cobbled together by a committee of amateurs and prima donnas: it was. mjr. _______________________________________________ firewall-wizards mailing list firewall-wizards () listserv icsalabs com https://listserv.icsalabs.com/mailman/listinfo/firewall-wizards
Current thread:
- Re: How automate firewall tests, (continued)
- Re: How automate firewall tests StefanDorn (Aug 20)
- Re: How automate firewall tests Strabla Ruggero (Aug 20)
- Re: How automate firewall tests Shahin Ansari (Aug 20)
- Re: How automate firewall tests Patrick M. Hausen (Aug 21)
- Re: How automate firewall tests Paul D. Robertson (Aug 21)
- Re: How automate firewall tests Patrick M. Hausen (Aug 21)
- Re: How automate firewall tests Paul D. Robertson (Aug 21)
- Re: How automate firewall tests Patrick M. Hausen (Aug 21)
- Re: How automate firewall tests Paul D. Robertson (Aug 21)
- Re: How automate firewall tests Oliver Humpage (Aug 21)
- Re: How automate firewall tests Marcus J. Ranum (Aug 21)
- Re: How automate firewall tests Isaac Van Name (Aug 21)
- Re: How automate firewall tests Shahin Ansari (Aug 20)
- Re: How automate firewall tests Avishai Wool (Aug 22)
- Re: How automate firewall tests Bill Royds (Aug 21)
- Re: How automate firewall tests Chuck Swiger (Aug 21)
- Re: How automate firewall tests Bill Royds (Aug 22)