/* HINT: Search archives @ http://www.indyramp.com/masq/ before posting! */


>This might be just a little off-topic, but I'm wondering what doesn't
>impress you about the PIX?  I haven't had the time to look into this myself,
>but the other guy at the office has been looking at the latest and greatest
>PIX for a couple of months, because of it's ability to do user-based
>authentication (although nobody know HOW it does that).  We're running a
>comercial firewall on that super-robust OS right now (NT), but we'll be
>replacing that by summertime.  User-based policies are the big seller at
>this point, which is why we're looking at the pix.

the last time I looked at the PIX, it wasn't truely stateful.  It was
more of a mix of packet and stateful inspection.  Next, its expensive
for its performance, etc.  The user authentiation is done via
TACACS or RADIUS and it probably works by opening/closing conduits
or Dynamic Access lists.

Again.. its been a while since I've looked at the PIX so things might
have changed quite a bit.

--David
.----------------------------------------------------------------------------.
|  David A. Ranch - Linux/Networking/PC hardware         [EMAIL PROTECTED]  |
!----                                                                    ----!
`----- For more detailed info, see http://www.ecst.csuchico.edu/~dranch -----'

_______________________________________________
Masq maillist  -  [EMAIL PROTECTED]
Admin requests can be handled at http://www.indyramp.com/masq-list/ -- THIS INCLUDES 
UNSUBSCRIBING!
or email to [EMAIL PROTECTED]

PLEASE read the HOWTO and search the archives before posting.
You can start your search at http://www.indyramp.com/masq/
Please keep general linux/unix/pc/internet questions off the list.

Reply via email to