Was wondering what the advantage is, if any, of CBAC (Context Based Access Control) over Reflexive ACLs? Also, have any of you guys had any opportunities to play with IOS-CS and AAA?
Yup. Hackers can craft packets that have syn-ack bits and whatever other information they want in L3/L4 headers to get through packet filters. That is why stateful inspection is so important.
Thanks Clue.. It's funny. The CBTNuggets CCNA video said that this was a secure setup but made no reference to stateful packet inspection.. (Probably just trying to keep it on a CCNA level though)..
Question: On both sides of the scale.. Do you have any links that cover the hacker side of "crafting" these packets and/or the defensive side of protecting against... Just anything that stands out in your mind as a really good site/reference...
I should start a new thread here but i did look at that cert once. Seems that you need company endorsement (from the company you work for)??? You guys know anything about that?
This site uses cookies to help personalise content, tailor your experience and to keep you logged in if you register.
By continuing to use this site, you are consenting to our use of cookies.