From owner-freebsd-security@FreeBSD.ORG Thu Feb 19 16:30:52 2004 Return-Path: Delivered-To: freebsd-security@freebsd.org Received: from mx1.FreeBSD.org (mx1.freebsd.org [216.136.204.125]) by hub.freebsd.org (Postfix) with ESMTP id 5623316A4CE for ; Thu, 19 Feb 2004 16:30:52 -0800 (PST) Received: from web12606.mail.yahoo.com (web12606.mail.yahoo.com [216.136.173.229]) by mx1.FreeBSD.org (Postfix) with SMTP id 3A58943D1D for ; Thu, 19 Feb 2004 16:30:52 -0800 (PST) (envelope-from bj93542@yahoo.com) Message-ID: <20040220003052.41695.qmail@web12606.mail.yahoo.com> Received: from [128.226.68.47] by web12606.mail.yahoo.com via HTTP; Thu, 19 Feb 2004 16:30:52 PST Date: Thu, 19 Feb 2004 16:30:52 -0800 (PST) From: Dorin H To: Darren Reed In-Reply-To: <200402192315.i1JNFxo4004083@caligula.anu.edu.au> MIME-Version: 1.0 Content-Type: text/plain; charset=us-ascii cc: freebsd-security@freebsd.org Subject: Re: traffic normalizer for ipfw? X-BeenThere: freebsd-security@freebsd.org X-Mailman-Version: 2.1.1 Precedence: list List-Id: Security issues [members-only posting] List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , X-List-Received-Date: Fri, 20 Feb 2004 00:30:52 -0000 --- Darren Reed wrote: > In some mail from Bruce M Simpson, sie said: > > > > On Thu, Feb 19, 2004 at 01:02:16PM -0800, Dorin H > wrote: > > > Is there some way to configure ipfw to do > traffic normalizing ("scrubbing", as in ipf for > You mean pf, not ipf.. Right. > > normalizing is over rated as a firewall feature - > it's really > something that belongs in IDS software. > > Darren True, it's part of IDS. Nevertheless, do you think that traffic normalizing is useful? If yes, where would you have it (you need an inline device for it; move the IDS inline and becomes IPS, which, IMHO, is indeed something over rated:)? If not, do you know better ways to handle IDS evasions (other than network active mapping, which takes both time & resources and could be useful for small networks only probably)? TIA, /Dorin. __________________________________ Do you Yahoo!? Yahoo! Mail SpamGuard - Read only the mail you want. http://antispam.yahoo.com/tools