Skip site navigation (1)Skip section navigation (2)
Date:      25 Oct 1999 10:03:26 -0400
From:      Chris Shenton <cshenton@uucom.com>
To:        John <papalia@UDel.Edu>
Cc:        freebsd-questions@FreeBSD.ORG
Subject:   Re: O'reilly & firewalls - outdated?
Message-ID:  <lf66zv8rm9.fsf@Samizdat.uucom.com>
In-Reply-To: John's message of "Mon, 25 Oct 1999 00:12:40 -0400"
References:  <4.1.19991025001028.0093b100@unix01.voicenet.com>

next in thread | previous in thread | raw e-mail | index | archive | help
On Mon, 25 Oct 1999 00:12:40 -0400, John <papalia@UDel.Edu> said:

John> Hey all... I was looking at buying O'Reilly's "Building Internet
John> Firewalls" since it appears to be a highly recommended book by
John> both users as well as /etc/rc.firewall :)

John> I was wondering though - it was published Sept 1995... has
John> anything changed that much to make it outdated at this point?
John> Simply put I'm looking for a reference to provide some good
John> (great?) guidance for configuring IPFW and for understanding
John> what's going on.

The concepts are still valid, the principles remain the same. There
seems to be a shift from the  use of plugs/proxies to stateful packet
filters and NAT but that's implementation details. It's the best book
I've seen for hands-on understanding of firewalls.

But it's not going to be a direct guide to how to config a certain
package like IPFW, IPF, Cisco ACLs, TIS FWTK, etc. That's a good thing
-- learn the concepts, the figure out what syntax you need for the
package you've chosen. 

Learning the concepts first also helps you to evaluate which products
(or combinations of products) you'd prefer to implement, like FWTK,
NAT, IPF/IPFW, etc.


To Unsubscribe: send mail to majordomo@FreeBSD.org
with "unsubscribe freebsd-questions" in the body of the message




Want to link to this message? Use this URL: <https://mail-archive.FreeBSD.org/cgi/mid.cgi?lf66zv8rm9.fsf>