[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index] RE: [FW1] Linux/Checkpoint Statefull inspection comparison
Title: Linux/Checkpoint Statefull inspection comparison Hi Mark (and
list),
Netfilter (part of
the ipchains replacement), not exactly a part of the 2.4 kernel, is very
good and it does do stateful inspection through via its state module
(which incidentally, is how it tracks connections for NAT). It is extremely
flexible and very, very fast. In addition to stateful inspection it also
protects against a wide range of flood type attacks.
However, this
flexibility comes at a cost. It is painful to set up (in comparison to FW1 at
any rate). Unless you are very comfortable with the older ipchains and have a
solid understanding of TCP/UDP/ICMP packet structure, stick with
FW1.
You might want to
check out the following URLs if you are still interested:
Matthew Ostwald
Network Engineer Speedwell Media Pty Ltd Phone: (07) 3236 9737 Fax: (07) 3236 9738 Level 10, Leichardt St PO Box 293 Spring Hill, Queensland 4004, Australia
|