ruinebabine
September 22nd, 2008, 08:20 AM
From that thread (http://www.wilderssecurity.com/showthread.php?t=182277&highlight=treeWalk) (that is too old to be replied to):-{ Quote: "ICMP state table (ICMP Pseudo SPI): On first look, from the ability to make the rule (for ping) outbound only, it would indicate state table, but the lack in logging of ICMP within 8signs makes this unclear at this time. (this was just a quick setup).
[...]
I will try to find time to make a better setup to check on this further.
EDIT:
While still setup I had a quick look at the TCP SPI,.... this is either very bad at logging or bad at filtering." }-
Hi Stem,
I don't know if you had intents and/or time to check this matter further, but I'd be very interested to know your findings on 8Signs filtering/logging capabilities and acuracy.
Or if it would be possible for you to provide me with a kinda simple procedure to guide me, I'd be willing to try to investigate it myself and report here my results for your reviewing...
Any ways, thanks for your help.
EDIT: Please note that the 8Signs more uptodate version is labelled as v3.0.37 at http://www.8signs.com/firewall/download.cfm, but it's confusing because the About window simply says version 3.03 while the binary file states v3.0.8.0307 and v3.0.4.1...
203090
[...]
I will try to find time to make a better setup to check on this further.
EDIT:
While still setup I had a quick look at the TCP SPI,.... this is either very bad at logging or bad at filtering." }-
Hi Stem,
I don't know if you had intents and/or time to check this matter further, but I'd be very interested to know your findings on 8Signs filtering/logging capabilities and acuracy.
Or if it would be possible for you to provide me with a kinda simple procedure to guide me, I'd be willing to try to investigate it myself and report here my results for your reviewing...
Any ways, thanks for your help.
EDIT: Please note that the 8Signs more uptodate version is labelled as v3.0.37 at http://www.8signs.com/firewall/download.cfm, but it's confusing because the About window simply says version 3.03 while the binary file states v3.0.8.0307 and v3.0.4.1...
203090