lists.openwall.net   lists  /  announce  owl-users  owl-dev  john-users  john-dev  passwdqc-users  yescrypt  popa3d-users  /  oss-security  kernel-hardening  musl  sabotage  tlsify  passwords  /  crypt-dev  xvendor  /  Bugtraq  Full-Disclosure  linux-kernel  linux-netdev  linux-ext4  linux-hardening  linux-cve-announce  PHC 
Open Source and information security mailing list archives
 
Hash Suite: Windows password security audit tool. GUI, reports in PDF.
[<prev] [next>] [<thread-prev] [thread-next>] [day] [month] [year] [list]
From: gem at rellim.com (Gary E. Miller)
Subject: PIX vs CheckPoint

-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

Yo Eric!

On Tue, 29 Jun 2004, Eric Paynter wrote:

> Easy to use in a "Microsoft" kind of way. Last I heard, it does nice
> things for you like always allow DNS traffic through, even if you have no
> port 53 rule and a deny all policy. How helpful!

You can override the hidden rules, but it takes some real digging.  Not
something the average admin can grasp.  At least you can teach the
average admin how to be somewhat usefull on the FW-1.  Teaching
someone the PIX is a PITA and the non-obvousness is rampant.

I prefer iptables on Linux, but do not even try to explain to anyone
else how it works.

RGDS
GARY
- ---------------------------------------------------------------------------
Gary E. Miller Rellim 20340 Empire Blvd, Suite E-3, Bend, OR 97701
	gem@...lim.com  Tel:+1(541)382-8588 Fax: +1(541)382-8676

-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.2.3 (GNU/Linux)

iD8DBQFA4d/n8KZibdeR3qURAvcOAJ0Rce8MZ6FtsRiMoFUFtYQ0I8lNwQCfQ84Z
Nkl9dYVDiz/E2jb4hlOvDUY=
=bWg5
-----END PGP SIGNATURE-----


Powered by blists - more mailing lists

Powered by Openwall GNU/*/Linux Powered by OpenVZ