Asymmetric Routing Around the Firewall
devnonsense.com
Asymmetric Routing Around the Firewall
1–10 of 16 posts
Re: Asymmetric Routing Around the Firewall
#2If I were on their infosec team I wouldn't ignore it, but also, infosec and network often different silos. If network was already notified, infosec can't do much but complain.
And, it seems the network was somewhat secure anyway. Any inbound scan or malicious traffic would get dropped going outbound, since there was no session on the outbound firewall.
Re: Asymmetric Routing Around the Firewall
#3Re: Asymmetric Routing Around the Firewall
#4>Later, when I realized that inbound traffic was bypassing the firewall, I notified UC Berkeley’s Information Security Office of the potential security vulnerability, but their response was somewhat lacking in urgency. So we’ll see. If I were on their infosec team I wouldn't ignore it, but also, infosec and network often different silos. If network was already notified, infosec can't do much but complain. And, it see…
There are lots of types of maliciousness that would not be affected by this.
Re: Asymmetric Routing Around the Firewall
#5Re: Asymmetric Routing Around the Firewall
#6>Later, when I realized that inbound traffic was bypassing the firewall, I notified UC Berkeley’s Information Security Office of the potential security vulnerability, but their response was somewhat lacking in urgency. So we’ll see. If I were on their infosec team I wouldn't ignore it, but also, infosec and network often different silos. If network was already notified, infosec can't do much but complain. And, it see…
> Any inbound scan or malicious traffic would get dropped going outbound There are lots of types of maliciousness that would not be affected by this.
Re: Asymmetric Routing Around the Firewall
#7Also usually firewalls are not decreasing packets IP TTL which make them invisble to traceroute.
You are lucky this one does not.
Re: Asymmetric Routing Around the Firewall
#8Re: Asymmetric Routing Around the Firewall
#9Re: Asymmetric Routing Around the Firewall
#10I would think that a network that even has a physical path capable of bypassing a firewall would be considered broken by design... Or at least insecure.