<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Firewall Wizards (firewall-wizards) Mailing List</title>
<link>http://seclists.org/#firewall-wizards</link>
<atom:link href="http://seclists.org/rss/firewall-wizards.rss" rel="self" type="application/rss+xml" />
<description>Tips and tricks for firewall administrators</description>
<language>en-us</language><ttl>60</ttl>
<item><title>Palo Alto Networks</title><description>Posted by Cassell Damon Z. on Dec 2&lt;p&gt;


&lt;p&gt;
Has anyone on the list had experience with firewalls from Palo Alto Networks? I am interested in real world experiences with these devices. Palo Alto is very new, so there is not much out there except marketing material. 
&lt;br /&gt;
&lt;p&gt;You can contact me off-list if you&#39;d prefer.
&lt;br /&gt;
&lt;p&gt;Thanks,
&lt;br /&gt;
&lt;p&gt;Damon Cassell
&lt;br /&gt;...</description>
<link>http://seclists.org/firewall-wizards/2008/Dec/0004.html</link><guid isPermaLink="true">http://seclists.org/firewall-wizards/2008/Dec/0004.html</guid>
<pubDate>Tue, 2 Dec 2008 08:32:18 -0500</pubDate></item>
<item><title>Re:  Layer 3  Layer 7 integration</title><description>Posted by à aditya mukadam à on Dec 2&lt;p&gt;


&lt;p&gt;
On Fri, Nov 28, 2008 at 8:53 PM, P OS
&lt;br /&gt;
&amp;lt;research.questions.contact_at_googlemail&amp;#46;com&amp;gt; wrote:
&lt;br /&gt;
&amp;gt; Hello All,
&lt;br /&gt;
&amp;gt;     We have a Netscreen firewall, but we are also open to other
&lt;br /&gt;
&amp;gt; alternatives. I am wondering if the following is possible:
&lt;br /&gt;
&amp;gt;
&lt;br /&gt;
&amp;gt; - clients connect to our...</description>
<link>http://seclists.org/firewall-wizards/2008/Dec/0003.html</link><guid isPermaLink="true">http://seclists.org/firewall-wizards/2008/Dec/0003.html</guid>
<pubDate>Tue, 2 Dec 2008 08:34:52 +0530</pubDate></item>
<item><title>Re:  Layer 3  Layer 7 integration</title><description>Posted by Lord Sporkton on Nov 30&lt;p&gt;


&lt;p&gt;
I dont think i understand fully what you asking. It sounds like you
&lt;br /&gt;
have some custom app that works in client server mode that hands out
&lt;br /&gt;
IPs? and you want to inspect it? I think....
&lt;br /&gt;
&lt;p&gt;Its almost impossible to do app layer inspection on a custom protocol,
&lt;br /&gt;
you would have to write you own...</description>
<link>http://seclists.org/firewall-wizards/2008/Dec/0002.html</link><guid isPermaLink="true">http://seclists.org/firewall-wizards/2008/Dec/0002.html</guid>
<pubDate>Sun, 30 Nov 2008 18:09:39 -0800</pubDate></item>
<item><title>Re:  DMZ Routing Question</title><description>Posted by Farrukh Haroon on Nov 29&lt;p&gt;


&lt;p&gt;
Considering the limited throughput on the firewalls as compared to a
&lt;br /&gt;
SUP720......I would do all the advanced routing/PBR on the switch.
&lt;br /&gt;
&lt;p&gt;Regards
&lt;br /&gt;
&lt;p&gt;Farrukh Haroon
&lt;br /&gt;
CCIE # 20184 (Security)
&lt;br /&gt;
&lt;p&gt;P.S. The ASA does not support PBR to date.
&lt;br /&gt;
&lt;p&gt;&lt;p&gt;&lt;p&gt;On Fri, Nov 28, 2008 at 1:07 AM, FW Mailinglist...</description>
<link>http://seclists.org/firewall-wizards/2008/Dec/0001.html</link><guid isPermaLink="true">http://seclists.org/firewall-wizards/2008/Dec/0001.html</guid>
<pubDate>Sat, 29 Nov 2008 08:51:27 +0300</pubDate></item>
<item><title>Re:  asa 5520</title><description>Posted by à aditya mukadam à on Nov 28&lt;p&gt;


&lt;p&gt;
In policy based NAT, you can define ACLs and then use that to perform
&lt;br /&gt;
the required translations.
&lt;br /&gt;
&lt;p&gt;Thanks,
&lt;br /&gt;
Aditya Govind Mukadam
&lt;br /&gt;
&lt;p&gt;On Thu, Nov 20, 2008 at 2:07 AM, Dave Love &amp;lt;dlove_at_verticalsystemsinc&amp;#46;net&amp;gt; wrote:
&lt;br /&gt;
&amp;gt; I want to know if it is possible to have one global outside nat...</description>
<link>http://seclists.org/firewall-wizards/2008/Nov/0028.html</link><guid isPermaLink="true">http://seclists.org/firewall-wizards/2008/Nov/0028.html</guid>
<pubDate>Fri, 28 Nov 2008 12:25:54 +0530</pubDate></item>
<item><title>Layer 3  Layer 7 integration</title><description>Posted by P OS on Nov 28&lt;p&gt;


&lt;p&gt;
Hello All,
&lt;br /&gt;
&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;We have a Netscreen firewall, but we are also open to other
&lt;br /&gt;
alternatives. I am wondering if the following is possible:
&lt;br /&gt;
&lt;p&gt;- clients connect to our system using a custom protocol on top of TCP/IP
&lt;br /&gt;
&lt;p&gt;- a unique userId will be used to identify each user, as source ip...</description>
<link>http://seclists.org/firewall-wizards/2008/Nov/0027.html</link><guid isPermaLink="true">http://seclists.org/firewall-wizards/2008/Nov/0027.html</guid>
<pubDate>Fri, 28 Nov 2008 15:23:24 +0000</pubDate></item>
<item><title>DMZ Routing Question</title><description>Posted by FW Mailinglist on Nov 27&lt;p&gt;


&lt;p&gt;
All,
&lt;br /&gt;
I have searched the archives a bit, but haven&#39;t found what I am looking for.
&lt;br /&gt;
I am implementing a new DMZ design and wanted to get back what the common
&lt;br /&gt;
consensus is on routing. I am deploying a typical sandwich design - Outside
&lt;br /&gt;
Firewall -&amp;gt; DMZ Networks &amp;lt;-Inside Firewall.
&lt;br /&gt;
&lt;p&gt;The...</description>
<link>http://seclists.org/firewall-wizards/2008/Nov/0026.html</link><guid isPermaLink="true">http://seclists.org/firewall-wizards/2008/Nov/0026.html</guid>
<pubDate>Thu, 27 Nov 2008 14:07:29 -0800</pubDate></item>
<item><title>Re:  VPN NAT issue</title><description>Posted by Lord Sporkton on Nov 26&lt;p&gt;


&lt;p&gt;
I have to this date, never needed an ACL to allow in VPN traffic on
&lt;br /&gt;
the outside interface. In the case of ipsec(ive not dealt with pptp to
&lt;br /&gt;
much) i dont even need an acl rule to allow the esp and udp 500
&lt;br /&gt;
traffic in.
&lt;br /&gt;
&lt;p&gt;I can post working configs if anyone would care to discuss with me why
&lt;br /&gt;
an acl...</description>
<link>http://seclists.org/firewall-wizards/2008/Nov/0025.html</link><guid isPermaLink="true">http://seclists.org/firewall-wizards/2008/Nov/0025.html</guid>
<pubDate>Wed, 26 Nov 2008 23:41:29 -0800</pubDate></item>
<item><title>pix to iptables conversion script?</title><description>Posted by david_at_lang.hm on Nov 26&lt;p&gt;


&lt;p&gt;
does anyone have a script that will convert a pix ruleset to iptables?
&lt;br /&gt;
&lt;p&gt;it&#39;s not _that_ hard to write one, but if someone has already done so...
&lt;br /&gt;
&lt;p&gt;David Lang
&lt;br /&gt;</description>
<link>http://seclists.org/firewall-wizards/2008/Nov/0024.html</link><guid isPermaLink="true">http://seclists.org/firewall-wizards/2008/Nov/0024.html</guid>
<pubDate>Wed, 26 Nov 2008 10:17:09 -0800 (PST)</pubDate></item>
<item><title>Re:  asa 5520</title><description>Posted by Pedro Henrique Morsch Mazzoni on Nov 26&lt;p&gt;


&lt;p&gt;
It is. See policy NAT.
&lt;br /&gt;
&lt;p&gt;Regards,
&lt;br /&gt;
Pedro Mazzoni
&lt;br /&gt;
&lt;p&gt;2008/11/19 Dave Love &amp;lt;dlove_at_verticalsystemsinc&amp;#46;net&amp;gt;
&lt;br /&gt;
&lt;p&gt;&amp;gt;  I want to know if it is possible to have one global outside nat address
&lt;br /&gt;
&amp;gt; and use it to route traffic to two separate internal ips based on source
&lt;br /&gt;
&amp;gt; address?
&lt;br /&gt;
&amp;gt;
&lt;br /&gt;
...</description>
<link>http://seclists.org/firewall-wizards/2008/Nov/0023.html</link><guid isPermaLink="true">http://seclists.org/firewall-wizards/2008/Nov/0023.html</guid>
<pubDate>Wed, 26 Nov 2008 15:38:48 -0200</pubDate></item>
<item><title>Re:  Cisco ASA 8.0(3) with RSA SecurID</title><description>Posted by Pedro Henrique Morsch Mazzoni on Nov 26&lt;p&gt;


&lt;p&gt;
Maybe you could try Cisco ACS to centralize your AAA. It´s not that good but
&lt;br /&gt;
it has no substitute to all features it delivers.
&lt;br /&gt;
Cisco ACS will pass authentication requestes to RSA and will deal with
&lt;br /&gt;
authorization and accounting.
&lt;br /&gt;
&lt;p&gt;Regards,
&lt;br /&gt;
Pedro Mazzoni
&lt;br /&gt;
&lt;p&gt;2008/11/26 Todd Simons...</description>
<link>http://seclists.org/firewall-wizards/2008/Nov/0022.html</link><guid isPermaLink="true">http://seclists.org/firewall-wizards/2008/Nov/0022.html</guid>
<pubDate>Wed, 26 Nov 2008 15:15:09 -0200</pubDate></item>
<item><title>Re:  Windows dynamic ARP</title><description>Posted by Mike OConnor on Nov 26&lt;p&gt;


&lt;p&gt;
:Does anyone know a way to turn OFF dynamic ARP on Windows?  I&#39;d like to
&lt;br /&gt;
:set up a network where static ARP entries are the only way to
&lt;br /&gt;
:communicate.
&lt;br /&gt;
&lt;p&gt;You might want to consider tweaking the StrictArpUpdate registry entry:
&lt;br /&gt;
http://technet.microsoft.com/en-us/library/cc739819.aspx
&lt;br /&gt;
&lt;p&gt;...</description>
<link>http://seclists.org/firewall-wizards/2008/Nov/0021.html</link><guid isPermaLink="true">http://seclists.org/firewall-wizards/2008/Nov/0021.html</guid>
<pubDate>Wed, 26 Nov 2008 16:51:30 +0000</pubDate></item>
<item><title>Re:  Cisco ASA IKE Initiator unable to find policy</title><description>Posted by Lord Sporkton on Nov 26&lt;p&gt;


&lt;p&gt;
Is there anything special about these site to site tunnels? Aggressive
&lt;br /&gt;
mode? or anything like that?
&lt;br /&gt;
&lt;p&gt;Do you have any further debug messages?
&lt;br /&gt;
&lt;p&gt;Lawrence
&lt;br /&gt;
&lt;p&gt;&lt;p&gt;2008/11/12 Jens Brey &amp;lt;jens_at_chaos-co&amp;#46;de&amp;gt;:
&lt;br /&gt;
&amp;gt; Dear all,
&lt;br /&gt;
&amp;gt;
&lt;br /&gt;
&amp;gt; i have the following problem. I have a ASA 5520 running 8.0.4....</description>
<link>http://seclists.org/firewall-wizards/2008/Nov/0020.html</link><guid isPermaLink="true">http://seclists.org/firewall-wizards/2008/Nov/0020.html</guid>
<pubDate>Wed, 26 Nov 2008 09:49:09 -0800</pubDate></item>
<item><title>Re:  VPN NAT issue</title><description>Posted by Lord Sporkton on Nov 26&lt;p&gt;


&lt;p&gt;
You want a NAT exemption on the IN2 interface
&lt;br /&gt;
so like
&lt;br /&gt;
nat (IN2) 0 access-list no-nat
&lt;br /&gt;
&lt;p&gt;where no-nat defines traffic from IN2 -&amp;gt; VPN_POOL
&lt;br /&gt;
&lt;p&gt;Lawrence
&lt;br /&gt;
&lt;p&gt;&lt;p&gt;2008/11/12 Vladislav Antolik &amp;lt;vladislav.antolik_at_gmail&amp;#46;com&amp;gt;:
&lt;br /&gt;
&amp;gt; Hello,
&lt;br /&gt;
&amp;gt;
&lt;br /&gt;
&amp;gt; I&#39;m using Cisco PIX 515E with 8.0(3) image.
&lt;br /&gt;
...</description>
<link>http://seclists.org/firewall-wizards/2008/Nov/0019.html</link><guid isPermaLink="true">http://seclists.org/firewall-wizards/2008/Nov/0019.html</guid>
<pubDate>Wed, 26 Nov 2008 09:46:21 -0800</pubDate></item>
<item><title>Re:  Windows dynamic ARP</title><description>Posted by Darden Patrick S. on Nov 26&lt;p&gt;


&lt;p&gt;
I don&#39;t think this will help.  The Gratuitous ARP is sent out when the windows machine is first booting up--it is checking to see if it is duplicating anybody&#39;s IP address.
&lt;br /&gt;
&lt;p&gt;--p
&lt;br /&gt;
&lt;p&gt;-----Original Message-----
&lt;br /&gt;
From: firewall-wizards-bounces_at_listserv&amp;#46;icsalabs.com
&lt;br /&gt;...</description>
<link>http://seclists.org/firewall-wizards/2008/Nov/0018.html</link><guid isPermaLink="true">http://seclists.org/firewall-wizards/2008/Nov/0018.html</guid>
<pubDate>Wed, 26 Nov 2008 11:49:52 -0500</pubDate></item>
</channel></rss>