Re: Use of single port aggregations to enhance security
ArkanoiD <[email protected]>
| Newsgroups | gmane.comp.security.firewalls.wizards |
|---|---|
| Message-ID | <[email protected]> |
I thought *every* operating system follows the rule "apply packet filtering first, bring interfaces up later" nowdays? On Wed, Jan 06, 2010 at 06:12:46AM +1100, Darren Reed wrote: > So what difference can this make? > > If you're using an operating system based firewall (Linux, > BSD, Solaris), then depending on the order of the operating > system enabling firewalls capabilities vs networking, there > may be windows where packets are able to reach code paths > that they weren't intended for because nic drivers start > servicing packets quite early.