Firewall-1 Behavior Receiving and Sending to Same Segment
am 24.09.2006 20:58:55 von CHANGE USERNAME TO westes
If Firewall-1 on Windows receives a packet on a segment that is destined for
the same segment, will the packet be subjected to the Firewall-1 rules
before it is (possibly) passed back to the segment?
--
Will
Re: Firewall-1 Behavior Receiving and Sending to Same Segment
am 26.09.2006 22:31:05 von larstr
In article you wrote:
: If Firewall-1 on Windows receives a packet on a segment that is destined for
: the same segment, will the packet be subjected to the Firewall-1 rules
: before it is (possibly) passed back to the segment?
No. This is something that used to be possible in some ancient versions
of firewall-1, but no more. The reason for this is that the OS might
issue an icmp redirect packet to the host which in turn will create a
temporary static route and then this trafic will bypass the firewall
totally.
Lars
Re: Firewall-1 Behavior Receiving and Sending to Same Segment
am 26.09.2006 23:20:11 von Will
wrote in message
news:efc2m9$v7u$1@bork.aitel.hist.no...
> In article you wrote:
> : If Firewall-1 on Windows receives a packet on a segment that is destined
for
> : the same segment, will the packet be subjected to the Firewall-1 rules
> : before it is (possibly) passed back to the segment?
>
> No. This is something that used to be possible in some ancient versions
> of firewall-1, but no more. The reason for this is that the OS might
> issue an icmp redirect packet to the host which in turn will create a
> temporary static route and then this trafic will bypass the firewall
> totally.
So what is the current behavior? The packet is automatically deleted or
passed?
--
Will