View Single Post
Old 12-01-2003, 06:02 AM   #14 (permalink)
Pragma
I am Winter Born
 
Pragma's Avatar
 
Location: Alexandria, VA
Cisco PIX boxes still aren't the be all and end all of firewalls.

To repeat: Any firewall, unless you set it up properly, is insecure. This includes PIX firewalls.

I've got an OpenBSD machine I use as my "firewall" - it's got very few open ports (less than the fingers on one hand), and OpenBSD is a very secure OS (Only one remote hole in the default install, in more than 7 years). I consider that to be "good enough" for my purposes.

Given OpenBSD's security record, I feel that I can discount the "firewall getting hacked" possibility and concentrate on just the packet filtering job of the firewall.

And, just for fun, I did a quick google search for you, -Anders:
A year-ish old vulnerability report from Cisco on their PIX firewalls. Everything has holes. Everything.
__________________
Eat antimatter, Posleen-boy!
Pragma is offline  
 

1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 38 39 40 41 42 43 44 45 46 47 48 49 50 51 52 53 54 55 56 57 58 59 60 61 62 63 64 65 66 67 68 69 70 71 72 73