Quote:
Originally posted by iNViCTuS
OK...please tell me a major vulnerability that has ever been discovered in a Checkpoint firewall. Big deal, a DoS here or there or maybe a malformed packet vulnerability. A firewall is more about the firewall admin than it is the type of firewall.
EVERYTHING has vulnerabilities...only the big players get scrutinized for every vulnerability that is uncovered (i.e. Microsoft, checkpoint, etc) That is why it is important to apply patches and updates. Of course an unmanaged firewall is useless to begin with.
I have been working with Checkpoint firewalls for a long time, so believe me, I have done my homework.
And as far as a Unix firewall is concerned, you cannot easily manage multiple firewalls within a single interface like you can with Checkpoint or Cisco. So that is what I meant by being afraid of them. Many organizations do not have the in-house talent to manage IPF, IPTABLES, IPCHAINS, etc. We know it is not that difficult, but many organizations still do not trust these types of applications because they are not highly publicized.