The Seattle SAGE Group (SSG)

Seattle based special interest group for system and network administrators.

Presentation at March 13, 1997 Meeting


Selecting a Firewall

Carl Brown

Pencom Systems Administration


What am I talking about?


How do you select a firewall?


Types of firewalls


Packet Filters


Can only filter based on content


Filtering Rules


Filtering Example


Stateful Packet Filters


Address Translation/Masquerading


Limitations


Proxies


"Standard" proxies


Transparent Proxies


Content Screening Examples


Limitations


Failure Modes


Screening Router


Dual-Homed Proxy


DMZ/Screened Subnet


"Popular" Attacks


Buffer Overruns


"SYN" Denial of Service


Sendmail


Itty Bitty Packet


IP Spoofing


Return to
Seattle Sage Group Home Page