Full Disclosure mailing list archives
Re: PIX vs CheckPoint
From: "Eric Paynter" <eric () arcticbears com>
Date: Tue, 29 Jun 2004 18:27:38 -0700 (PDT)
On Tue, June 29, 2004 4:57 pm, Gary E. Miller said:
I agree, except for one small problem. Don't you still have to delete ALL the filter rules, and reenter them ALL to change the order of the rules?
I don't administer the PIX boxes, so I don't know the details of the interface. My statements were based on what the admins told me. However, isn't the beauty of any CLI app that you can do all your administration through simple scripts? Personally, I use iptables firewalls. With iptables, my "config" file is really the script that loads the rules. When I make a change to the rules, it is to add/alter/remove a line from that script. The script is executed on boot and after any changes. I would assume the same is standard practice for PIX. The other benefit of a scripted config is you can test it on another machine, and once you're sure you've got it right, you can copy the script over to the production machine. Reduces errors. You're not entering rules by hand into a production firewall, are you? :shock: -Eric _______________________________________________ Full-Disclosure - We believe in it. Charter: http://lists.netsys.com/full-disclosure-charter.html
Current thread:
- Re: PIX vs CheckPoint, (continued)
- Re: PIX vs CheckPoint Cyril Guibourg (Jun 30)
- Re: PIX vs CheckPoint Jaroslaw Sajko (Jun 30)
- Re: PIX vs CheckPoint Laurent LEVIER (Jun 30)
- Re: PIX vs CheckPoint Cyril Guibourg (Jun 30)
- RE: PIX vs CheckPoint James Patterson Wicks (Jun 29)
- RE: PIX vs CheckPoint Eric Paynter (Jun 29)
- RE: PIX vs CheckPoint Gary E. Miller (Jun 29)
- Re: PIX vs CheckPoint John Kinsella (Jun 29)
- Re: PIX vs CheckPoint Eric Paynter (Jun 29)
- RE: PIX vs CheckPoint Tom Curry (Jun 29)
- Re: PIX vs CheckPoint Gary E. Miller (Jun 29)
- Re: PIX vs CheckPoint Eric Paynter (Jun 29)
- Re: PIX vs CheckPoint Jeff Kell (Jun 29)
- Re: PIX vs CheckPoint Matt Ostiguy (Jun 29)
- Re: PIX vs CheckPoint Simon Burr (Jun 29)
- RE: PIX vs CheckPoint Eric Paynter (Jun 29)
- RE: PIX vs CheckPoint; IMHO Netscreen is far superior Edward W. Ray (Jun 29)
- RE: PIX vs CheckPoint; IMHO Netscreen is far superior Gary E. Miller (Jun 29)
- Re: PIX vs CheckPoint Jim Burwell (Jun 30)