Re: Firewall best practices

Martin Barry <[email protected]>
Newsgroups gmane.comp.security.firewalls.wizards
Message-ID <[email protected]>
$quoted_author = "Morty" ;
> 
> If you have IDS, your perspective might change because crypto-enabled
> ports cause you to lose insight.

...and every app that wants to work around a firewall just encrypts it's
traffic and runs the server on port 443.

It would be nice to not be "enumerating badness" and blacklisting IPs
running services on port 443 that are against corporate policy but trying
for "default deny and whitelist" would cause a DOS on support resources.

cheers
Marty
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.