Quote:
The default policies are just used when there is no policy installed on the FW module. Even those could be changed as mentioned earlier or as in defaultfilter.pf in phoneboy's book (Appendix F).
Also, if your using the GUI to create your rulebase, #include fwui_trail.def is added to the end, the file has on sole purpose "DROP whatever reaches it" ius that open by default? CP's only open ports are all stated in the Implied_Rules and NOWHERE ELSE.
That's it for Chsh, plus, jerald josephs is moderator on the fw1-wiz list, and Regional manager of nokia telecomunications in da east cost of the USA. The guys experience is only limited to his appliance <Nokia's IP series> and VPNs. He has mentioned no vulnerabilities in his post. the problems demonstrated at BH could be found on Phoneboy's site under Docs. Yet, as you see those problems are all mistakes by the ADMINs and not cause of CP.