Firewall Wizards mailing list archives
RE: CERT vulnerability note VU# 539363
From: "Stephen Gill" <gillsr () yahoo com>
Date: Wed, 16 Oct 2002 22:44:41 -0500
Indeed! The dest-ip option would only be used in certain circumstances, and generally to protect the whole (firewall) at the sacrifice of a few (a single rule). If you are referring to ScreenOS 4.0 I'd wait until 4.0.0r4 comes out. It will fix another vulnerability as well as a few bugs. It should be out any day now. Stability? It probably depends on your platform... I'm fairly comfortable with it, and if there's a problem you can always report it and usually bug fixes are pretty quick. Cheers, -- steve -----Original Message----- From: Philip J. Koenig [mailto:pjklist () ekahuna com] Sent: Wednesday, October 16, 2002 8:05 PM To: Firewall-wizards () honor icsalabs com Cc: Stephen Gill Subject: RE: CERT vulnerability note VU# 539363 On 16 Oct 2002 at 17:00, Stephen Gill boldly uttered:
In V4.0 the syntax has changed somewhat for the aforementioned
command,
though the concept still applies... set zone <zone> screen limit-session source-ip-based <threshold> I've requested something like set zone <zone> screen limit-session dest-ip-based <threshold> but I've not seen it in code yet. If I'm not mistaken I believe CP
has
added the ability to do both recently. -- steve
OK, but the nice thing about the source-based rule is it's not very likely to drop legitimate traffic (unless you misconfigure it without any sense of your normal traffic profile), whereas a destination- based rule could easily cause that problem, particularly for public servers. On a slightly off-topic note - do you find ScreenOS stable? I avoided it for stability reasons at a newly-deployed site but it would have been convenient to start off with it because when the time comes to upgrade it looks like I'll have to re-architect lots of the rules to adapt to its new syntax. -- Philip J. Koenig pjklist () ekahuna com Electric Kahuna Systems -- Computers & Communications for the New Millenium _______________________________________________ firewall-wizards mailing list firewall-wizards () honor icsalabs com http://honor.icsalabs.com/mailman/listinfo/firewall-wizards
Current thread:
- RE: CERT vulnerability note VU# 539363, (continued)
- RE: CERT vulnerability note VU# 539363 Stephen Gill (Oct 16)
- Re: CERT vulnerability note VU# 539363 Frank Knobbe (Oct 16)
- Re: CERT vulnerability note VU# 539363 Paul Robertson (Oct 16)
- Re: CERT vulnerability note VU# 539363 Martin (Oct 16)
- RE: CERT vulnerability note VU# 539363 Stephen Gill (Oct 16)
- Re: CERT vulnerability note VU# 539363 Mikael Olsson (Oct 16)
- RE: CERT vulnerability note VU# 539363 Stephen Gill (Oct 16)
- Re: CERT vulnerability note VU# 539363 Philip J. Koenig (Oct 16)
- RE: CERT vulnerability note VU# 539363 Stephen Gill (Oct 16)
- RE: CERT vulnerability note VU# 539363 Philip J. Koenig (Oct 16)
- RE: CERT vulnerability note VU# 539363 Stephen Gill (Oct 17)
- RE: CERT vulnerability note VU# 539363 Philip J. Koenig (Oct 16)
