In your previous mail you wrote:

   > => I fully support Vijay's opinion (and we had firewall persons
   > in our group).
   
   And these firewall persons were probably stateful (by themselves or by
   connection to AAA system) firewall evangelists?
   
=> by themselves: they are proud to offer one of the first firewalls
with portmap/rpcbind spoofing (i.e. the firewall looks at the port
negociated by portmap/rpcbind and opens a little door for it).
As I already said, IMHO stateful firewalls do a better job than
stateless firewalls (and I prefer to have *no* firewall on the network
I use, specially no firewall managed by another person :-).
We are leaving the mailing list scope...

Regards

[EMAIL PROTECTED]
--------------------------------------------------------------------
IETF IPng Working Group Mailing List
IPng Home Page:                      http://playground.sun.com/ipng
FTP archive:                      ftp://playground.sun.com/pub/ipng
Direct all administrative requests to [EMAIL PROTECTED]
--------------------------------------------------------------------

Reply via email to