Download TrojanHunter Now
Free 30-day trial!
Latest TrojanHunter Version:
TrojanHunter 5.0
Order Now
License file delivered within minutes.
Welcome, Guest. Please Login or Register.
Nov 20th, 2008, 11:23am
   Mischel Internet Security Forum
   Internet Security
   Firewalls
(Moderators: Helena, Gavin_Coe, Magnus)
   CHX-I  dedicated  Forum
« Previous topic | Next topic »
Pages: 1  Reply Reply  Notify of replies Notify of replies   Send Topic Send Topic   Print Print
   Author  Topic: CHX-I  dedicated  Forum  (Read 1607 times)
mozar
Highly Honored Mass-Poster
*******





   


Posts: 1524
CHX-I  dedicated  Forum
« on: Dec 6th, 2004, 4:44am »
Quote Quote  Modify Modify

 Hello  ,
 
  There  is  now  a  new  sub-forum  at  the Software Security Central   where  you  can  talk  about  this  free software  FW :
 
http://www.fluxgfx.com/ssc/
 
Just  search  for  the  section  :  "  CHX-I - General  "  
 
 
Or  use  the sub-forum's  direct  link  :
 
http://www.fluxgfx.com/ssc/forumdisplay.php?f=23
 
 
  Regards  ,
 
                mozar
 
 
 
 
 
« Last Edit: Dec 8th, 2004, 4:18pm by mozar » IP Logged
mozar
Highly Honored Mass-Poster
*******





   


Posts: 1524
Re: CHX-I  dedicated  Forum
« Reply #1 on: Dec 7th, 2004, 5:48am »
Quote Quote  Modify Modify

 BTW  ,  if  you  want  to  try  "CHX-I"  please read   all  the  on-line  documentation   and  download  the   Manual .
  And here  is  a  copy  of  the  developer's  " Must read " :
 
" ...In its default configuration the packet filter does not impose any security restrictions on any type of traffic.  
 
The CHX-I Packet Filter is not a personal firewall and should not be used by those expecting out-of-the box security configurations or unfamiliar with TCP/IP networking and IP security in general. Several configuration templates are provided to assist first time users in grasping CHX-I filtering concepts. These templates can be obtained in the idrci.net download area.  
 
First time users are encouraged to make extensive use of the available logging features (and the GoTo Related Filter feature) when debugging their CHX-I IP security policies.  
 
The packet filter cannot facilitate address/port translation in gateway environments. The CHX-I NAT module was designed to provide this functionality as either a stand alone or add-on to the packet filter management console.  ... "
 
And  ,  also  ,  this  one  here :
 
" ... Several rules of thumb that should be understood when creating packet filter policies:  
 
1. All traffic is first checked against static packet filter rules. If allowed - the traffic is then analyzed by the stateful inspection engine provided the state analysis options are enabled.  
 
2. "Allow" rules are Prohibitive. This means anything not specified in the Allow rules is automatically dropped.  
 
3. If the UDP "pseudo-stateful" option is enabled a Force Allow must be used when running UDP servers (e.g. DNS).  
 
4. If the ICMP "pseudo-stateful" option is enabled a Force Allow must be used when unsolicited ICMP traffic is allowed.  
 
4. A Force Allow acts as a trump card only within the same priority context.  
 
  ... "
 
 
 
« Last Edit: Dec 7th, 2004, 5:50am by mozar » IP Logged
Pages: 1  Reply Reply  Notify of replies Notify of replies   Send Topic Send Topic   Print Print

« Previous topic | Next topic »
Search
Members
Login
Register