Full Disclosure mailing list archives

RE: PIX vs CheckPoint


From: "Gary E. Miller" <gem () rellim com>
Date: Tue, 29 Jun 2004 14:32:20 -0700 (PDT)

-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

Yo Eric!

On Tue, 29 Jun 2004, Eric Paynter wrote:

Easy to use in a "Microsoft" kind of way. Last I heard, it does nice
things for you like always allow DNS traffic through, even if you have no
port 53 rule and a deny all policy. How helpful!

You can override the hidden rules, but it takes some real digging.  Not
something the average admin can grasp.  At least you can teach the
average admin how to be somewhat usefull on the FW-1.  Teaching
someone the PIX is a PITA and the non-obvousness is rampant.

I prefer iptables on Linux, but do not even try to explain to anyone
else how it works.

RGDS
GARY
- ---------------------------------------------------------------------------
Gary E. Miller Rellim 20340 Empire Blvd, Suite E-3, Bend, OR 97701
        gem () rellim com  Tel:+1(541)382-8588 Fax: +1(541)382-8676

-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.2.3 (GNU/Linux)

iD8DBQFA4d/n8KZibdeR3qURAvcOAJ0Rce8MZ6FtsRiMoFUFtYQ0I8lNwQCfQ84Z
Nkl9dYVDiz/E2jb4hlOvDUY=
=bWg5
-----END PGP SIGNATURE-----

_______________________________________________
Full-Disclosure - We believe in it.
Charter: http://lists.netsys.com/full-disclosure-charter.html


Current thread: