Re: ZoneAlarm Pro, Sygate Personal Firewall, or built in xp firewall?

From: CZ (CZ_at_no99spam.com)
Date: 05/21/04


Date: Fri, 21 May 2004 10:20:49 -0700


> ICF is stateful, and ZA is stateless, so ICF can provide technology that
ZA lacks

What is the difference, please explain.

Lars:
A stateless firewall can only drop a packet per info in that single packet.
A stateful firewall maintains a connection state table and can use
additional info to drop packets.

Examples:
1) ACK scan (aka TCP ping):
Hackers can send an ACK packet to see if an address is active.
A stateless f/w cannot drop the packet because it cannot verify if it is
part of an existing connection.
A stateful f/w can drop the packet per info in the connection state table.

2) Dynamic blocking of source address (SA) spoofing:
A stateless f/w cannot do it because it does not retain info from any
packet, a stateful f/w can use its table to verify the SA.

The above is before mktg gets involved. LinkSys started claiming SPI
(stateful packet inspection) as a feature of their routers several years
ago, and then would not clarify what the phrase meant. Tests by
knowledgeable people suggested the concept was not stateful.



Relevant Pages

  • Re: ipfw, natd, and keep-state - strange behavior?
    ... dfolkins wrote: ... but only if one allows stateful _incoming_ connections. ... as a stateless packet filter for a long time but when I first tried ipf ... In fact stateful packet filtering as ipf provide ...
    (FreeBSD-Security)
  • Re: [fw-wiz] CERT vulnerability note VU# 539363 (fwd)
    ... > In my experience, ruleset lookup hits on stateless packet ... > packet packet forwarding rules at the top of the ruleset. ...
    (Firewall-Wizards)
  • Re: stateful vs stateless
    ... How exactly the stateful and stateless doing in an IPS? ... Both the stateful and stateless are happened at the detection process, ...
    (Focus-IDS)
  • Re: Stateful Inspection
    ... stateful packet filters are slower than non stateful ... > memory and CPU time than non stateful packet filters. ... I guess it may be true to say that stateful firewalls may require more ... hardware to get the same performance as packet filtering routers, ...
    (comp.security.firewalls)
  • Re: Stateful Inspection
    ... stateful packet filters are slower than non stateful ... > memory and CPU time than non stateful packet filters. ... I guess it may be true to say that stateful firewalls may require more ... hardware to get the same performance as packet filtering routers, ...
    (comp.security.firewalls)