Penetration Testing mailing list archives

Re: Firewall rulebase checking tool


From: anthony.cicalla () gmail com
Date: Sat, 14 Aug 2010 18:50:53 +0000

Although it will not check your syntax only validate externally that what you implemented was in fact what you though 
it was. It allows you to test your rule set from the outside going in to walk the firewall and see what rules are 
actually in place. 
Sent via BlackBerry from T-Mobile

-----Original Message-----
From: anthony.cicalla () gmail com
Date: Sat, 14 Aug 2010 18:47:20 
To: Jirka Vejrazka<jirka.vejrazka () gmail com>; <listbounce () securityfocus com>; <pen-test () securityfocus com>
Reply-To: anthony.cicalla () gmail com
Subject: Re: Firewall rulebase checking tool

Fire walker I believe is the tool your looking for
Sent via BlackBerry from T-Mobile

-----Original Message-----
From: Jirka Vejrazka <jirka.vejrazka () gmail com>
Sender: listbounce () securityfocus com
Date: Fri, 13 Aug 2010 16:17:49 
To: <pen-test () securityfocus com>
Subject: Firewall rulebase checking tool

Hi all,

  I'm trying to figure out if there is a tool that would help
validating firewall rulebase(s), if the configuration is available
(i.e. no blind pen-testing, more like an audit)

  I know about Flint from Matasano security, looking for some other
options too. Ability to recognize iptables and CheckPoint syntax would
be great.

  Any hints appreciated

    Jirka

------------------------------------------------------------------------
This list is sponsored by: Information Assurance Certification Review Board

Prove to peers and potential employers without a doubt that you can actually do a proper penetration test. IACRB CPT 
and CEPT certs require a full practical examination in order to become certified. 

http://www.iacertification.org
------------------------------------------------------------------------


Current thread: