Greetings!
Russell Washington wrote:
This kind of stuff varies from vendor to vendor. NetScreen doesn't do
it, being more of a "pure firewall" device (as opposed to a content
filter, which is essentially what we're talking about here). However,
NetScreens offer WebSense integration capabilities.
Cisco stuff... Dunno. Probably not. Like I said, varies by vendor.
I'l like to suggest
s/pure firewall/packet filter/g;
For an overview of firewall types see e.g.
http://wyae.de/secure_gateway/gateways.php
Basically content inspection can be done two ways:
1.) Compare to patterns while passing the stream along (this is what
CKP' "Inspection" stuff is doing as well as a number of URL filters) -
and reset the connection as soon as there's something afoul. This
inspection is trademarked by CheckPoint. While it theoretically is
faster than proxies (no generation of passed-on packets), it lacks the
ability to alter the data stream.
2.) Have application-specific proxies (either transparent or
nontransparent) to accept the traffic, analyze it and forward the
acceptable parts (e.g. filter out the internal Received: lines from mail).
Cave!
The presence of a proxy does not guarantee that it checks anything at
all (infamous for this: any WinSOCKS-Proxy). At least any
protocol-specific proxy will kill packet-manipulations as the connection
ends at the firewall, which generates the new (forwarded) query anew.
While most "SOHO" firewalls are plain packet filters, a number of them
offers URL-filters (usually inspect-type technique). Most more serious
firewalls are of hybrid type and offer specialized proxies.
Due to marketing decisions proxies are not always recognizable as such.
CheckPoint calls them "ressources" or "security servers", Cisco (Pix
only) calls them "fixups".
And now? What is better? Proxy or Inspect?
Well, that depends on the actual implementation - and needs. For example
the Eagle/Axent/Symantec "Raptor"/"Enterprise" firewall has quite a
strict SMTP proxy. While this sounds good with respect to security it
can be hell to work with if you have a broken SMTP-Gateway which
generates mail headers that are not RfC-conform. A few years ago the
combination Raptor with LotusNotes was infamous for this.
And now? Which to choose?? Help!
Well, you'll have to decide your own. My suggestion: try to test all
that are within your profile (features/price). Try to talk with the
support techies on the implementation details if the sales person cannot
help further. This is a good chance to test the quality of the hotline,
too. If you don't have the resssources, experience, or time to acquire
the latter - hire a good consultant.
Bye
Volker Tanger
IT-Security Consulting
--
discon gmbh
Wrangelstra�e 100
D-10997 Berlin
fon +49 30 6104-3307
fax +49 30 6104-3461
[EMAIL PROTECTED]
http://www.discon.de/
=================================================
To set vacation, Out Of Office, or away messages,
send an email to [EMAIL PROTECTED]
in the BODY of the email add:
set fw-1-mailinglist nomail
=================================================
To unsubscribe from this mailing list,
please see the instructions at
http://www.checkpoint.com/services/mailing.html
=================================================
If you have any questions on how to change your
subscription options, email
[EMAIL PROTECTED]
=================================================