Firewall Wizards mailing list archives

Re: Firewall-Wizards Digest V1 #311


From: "Ryan Russell" <Ryan.Russell () sybase com>
Date: Thu, 3 Jun 1999 07:34:16 -0700




Why not simply check the data field for the SR tag? A real proxy should
be unable to forward traffic (source routed or not) without proxy
intervention.

Those types of things get stripped off before the daemon gets
the data, no?  Doesn't all the interesting info below layer 4 get
"eaten" by the OS by the time an app using sockets gets
it?

FW-1 doesn't do it..

Actually, it does. It has dropped SR by default since 2.1b or so. I
remember having to apply the patch. ;)

Sorry, I stand corrected.

                    Ryan






Current thread: