as far as I know (which aint much)..
FW1 "statefull inspection" is the only "filter" that really does what you say
you want.
acs
On 13-Apr-00 [EMAIL PROTECTED] wrote:
> "Aaron C. Springer" <[EMAIL PROTECTED]> wrote:
>> ipfilter
>>
>> http://www.openbsd.org/faq/faq6.html#6.2
>
> I don't really know much about ipfilter but from my browsing of the
> ipfilter web page -- specifically the section on "state"
> (http://coombs.anu.edu.au/~avalon/examples.html#packetstate), it looks
> _very_ rudimentary. From what I can tell it only follows generic TCP
> and UDP state and does not do any application protocol state tracking.
>
> b.
>
> -
> [To unsubscribe, send mail to [EMAIL PROTECTED] with
> "unsubscribe firewalls" in the body of the message.]
_______________________
Aaron C. Springer
[EMAIL PROTECTED]
pgp key published
_______________________
-
[To unsubscribe, send mail to [EMAIL PROTECTED] with
"unsubscribe firewalls" in the body of the message.]