That was exactly the answer I was looking for.

Amir Seyavash Mesry
[EMAIL PROTECTED]
LSI Logic Corporation
http://www.lsilogic.com/
Raid Support Test Technician
6145-D Northbelt Parkway
Norcross, GA 30071
678-728-1211
 
NOTICE: This communication may contain privileged or other 
confidential information. If you are not the intended recipient, or
believe that 
you have received this communication in error, please do not print,
copy, 
retransmit, disseminate, or otherwise use the information. Also, please
indicate 
to the sender that you have received this communication in error, and
delete the 
copy you received. Thank you.
 


-----Original Message-----
From: [EMAIL PROTECTED] [mailto:[EMAIL PROTECTED]] On Behalf
Of Philipp Buehler
Sent: Friday, August 30, 2002 9:43 AM
To: [EMAIL PROTECTED]
Subject: Re: Keepstate ?


On 30/08/2002, Daniel Hartmeier <[EMAIL PROTECTED]> wrote To
[EMAIL PROTECTED]:
> I'm not familiar with Cisco rule sets, so please explain what the 
> latter rule does, exactly.

cisco's 'established' lets anything 'in' where it thinks (!) that it
belongs to answering packets. such as fin/rst/syn-ack/ack packets. More
or less, anything except a pure 'syn'.

so consider this 'established' a subset of 'keep state' where the later
provides way more filtering security.
BEGIN:VCARD
VERSION:2.1
N:Mesry;Amir;Seyavash
FN:Amir Seyavash Mesry
ORG:LSI Logic Inc.;Raid
TITLE:Raid Support Test Technician
TEL;WORK;VOICE:(678) 728-1211
ADR;WORK:;;6145-D Northbelt Parkway;Norcross;GA;30071;United States of America
LABEL;WORK;ENCODING=QUOTED-PRINTABLE:6145-D Northbelt Parkway=0D=0ANorcross, GA 30071=0D=0AUnited States of Ameri=
ca
ADR;POSTAL:;;6145-D Northbelt Parkway;Norcross;GA;30071;United States of America
LABEL;POSTAL;ENCODING=QUOTED-PRINTABLE:6145-D Northbelt Parkway=0D=0ANorcross, GA 30071=0D=0AUnited States of Ameri=
ca
EMAIL;PREF;INTERNET:[EMAIL PROTECTED]
REV:20020510T175919Z
END:VCARD

Reply via email to