Re: PIX DMZ Denial of Service - TCP Resets

2000-03-22 Thread Andrew Alston
ust theory and I dont have a system to test it on, but any comments would be appreciated. Thanks Andrew Alston Citec Network Securities (Director) Phone: +27 11 787 4241 Fax: +27 11 787 4259 Cell: +27 83 602 5370 Email: [EMAIL PROTECTED]

PIX DMZ Denial of Service - TCP Resets

2000-03-20 Thread Andrew Alston
A brief rundown of the problem. If you run routable ips on your internal interface on your pix, and routeable ips on your external interface, so the pix is not running nat, the pix keeps a state table of everything going on. Anything that is not in your state table that attempts to come in from