Re: Use of single port aggregations to enhance security

[email protected]
Newsgroups gmane.comp.security.firewalls.wizards
Message-ID <[email protected]>
On Sat, 9 Jan 2010, ArkanoiD wrote:

> I thought *every* operating system follows the rule "apply
> packet filtering first, bring interfaces up later" nowdays?

They all can, but not all do by default. Worst case doing this takes 
inserting your rules in a custom init script that fires prior to the 
network startup.

David Lang

> On Wed, Jan 06, 2010 at 06:12:46AM +1100, Darren Reed wrote:
>> So what difference can this make?
>>
>> If you're using an operating system based firewall (Linux,
>> BSD, Solaris), then depending on the order of the operating
>> system enabling firewalls capabilities vs networking, there
>> may be windows where packets are able to reach code paths
>> that they weren't intended for because nic drivers start
>> servicing packets quite early.
>
> _______________________________________________
> firewall-wizards mailing list
> [email protected]
> https://listserv.icsalabs.com/mailman/listinfo/firewall-wizards
>
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.