On Tue, Jun 13, 2000 at 05:07:50AM -0700, Rogue Bolo wrote:
 
> I am guessing that the ACL option on the Nokia is
> strictly for people who can't seem to get it out of
> their heads that stateful inspection makes more sense
> than ACLs. For the truly paranoid the Nokia also has
> route filters.

ACLs are used to implement rate shaping as well. The Nokia's have
this capability built-in, i.e. you don't need Floodgate. ACLs are
applied before FireWall-1 sees the packets.

-- PhoneBoy


================================================================================
     To unsubscribe from this mailing list, please see the instructions at
               http://www.checkpoint.com/services/mailing.html
================================================================================

Reply via email to