Skip site navigation (1)Skip section navigation (2)
Date:      Sun, 05 Sep 2010 23:59:38 -0700
From:      Doug Barton <dougb@FreeBSD.org>
To:        Adrian Chadd <adrian@freebsd.org>
Cc:        freebsd-current@freebsd.org, Luigi Rizzo <rizzo@iet.unipi.it>, Anderson Eduardo <listas@secover.com.br>
Subject:   Re: Using ipfw table names instead of numbers.
Message-ID:  <4C84915A.1000703@FreeBSD.org>
In-Reply-To: <AANLkTi=Z_wV8rtNqfzPJn8Hg0vat1s-vrmnJsnA0D0mE@mail.gmail.com>
References:  <4C825094.5040204@secover.com.br>	<20100905155311.GA48095@onelab2.iet.unipi.it>	<4C84364D.9070700@DataIX.net> <AANLkTi=Z_wV8rtNqfzPJn8Hg0vat1s-vrmnJsnA0D0mE@mail.gmail.com>

next in thread | previous in thread | raw e-mail | index | archive | help
On 09/05/2010 11:47 PM, Adrian Chadd wrote:
> I'd argue that "DNS" clue pushes the firewall out from a packet
> inspection thing and into a user-space application inspection thing.

It also opens up an attack vector on your firewall.


Doug

-- 

	Improve the effectiveness of your Internet presence with
	a domain name makeover!    http://SupersetSolutions.com/

	Computers are useless. They can only give you answers.
			-- Pablo Picasso




Want to link to this message? Use this URL: <https://mail-archive.FreeBSD.org/cgi/mid.cgi?4C84915A.1000703>