On Tue, 2009-11-10 at 10:44 -0600, James Slepicka wrote: 
> Just keep in mind that traffic through the firewalls usually* needs to
> be symmetric.  Be sure to account for that in your design.
> 
> * 
> https://www.cisco.com/en/US/docs/security/asa/asa82/configuration/guide/conns_tcpstatebypass.html

I've read about this, but I fail to see what the point is. If the
firewall doesn't do stateful inspection, then why use a firewall? Why
not just a router/switch with L4 ACLs?

What am I missing?

-- 
Peter


_______________________________________________
cisco-nsp mailing list  [email protected]
https://puck.nether.net/mailman/listinfo/cisco-nsp
archive at http://puck.nether.net/pipermail/cisco-nsp/

Reply via email to