Re: need for stateful packet inspection

[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

 



On Sun, 2004-05-23 at 18:33, Randolph Jones wrote:
> I am ignorant re iptables.
> 
> I am considering buying a linksys router. It seems to have statefull 
> packet inspection that blocks nonmatching incoming packets.
> 
> If I do not have a server exposed to the internet, do I need any
> packet inspection other than checking that all incoming packets match an 
> earlier outgoing request?
> 
> TIA
> rfjones
In short, no.  If your needs are minimal and you do not need to managed
multiple devices a linksys may be fine for you.  I cannot speak to the
quality of Linksys; I have not used them.  However, not all stateful
inspection engines are created equal.  Consider what functionality you
may need in the future.  Consider how important reliability is, i.e., 
if the device occasionally fails and needs to be reset, is that a
problem. However, for very simple needs, a Linksys will probably be
fine.
Does anyone else have any thoughts, comments or insults?
-- 
John A. Sullivan III
Chief Technology Officer
Nexus Management
+1 207-985-7880
john.sullivan@xxxxxxxxxxxxx
---
If you are interested in helping to develop a GPL enterprise class
VPN/Firewall/Security device management console, please visit
http://iscs.sourceforge.net 



[Index of Archives]     [Linux Netfilter Development]     [Linux Kernel Networking Development]     [Netem]     [Berkeley Packet Filter]     [Linux Kernel Development]     [Advanced Routing & Traffice Control]     [Bugtraq]

  Powered by Linux