>         Just a quick question, I am being asked if a rule in NG can be
> specifically configured to drop NON RFC 2246 compliant traffic. This
is a
> first for me.......
>
> Has anyone done this?

In short? It can't be done.

You can run many different protocols over TLS. Like http over TLS, FTP
over TLS etc... The problem is that protocol communication is encrypted
thus FW can't do any packet inspection and has to "fly blind". I had
some experience with FTP/TLS (HTTPS) and for sure it can not go over
firewall.

Basically what you asking is to drop all non-encrypted traffic.

=================================================
To set vacation, Out Of Office, or away messages,
send an email to [EMAIL PROTECTED]
in the BODY of the email add:
set fw-1-mailinglist nomail
=================================================
To unsubscribe from this mailing list,
please see the instructions at
http://www.checkpoint.com/services/mailing.html
=================================================
If you have any questions on how to change your
subscription options, email
[EMAIL PROTECTED]
=================================================

Reply via email to