<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Comments on: Protecting your juniper router from PSN-2010-01-623 using Firewall filters</title>
	<atom:link href="http://www.toonk.nl/blog/?feed=rss2&#038;p=522" rel="self" type="application/rss+xml" />
	<link>http://www.toonk.nl/blog/?p=522</link>
	<description>The weblog  of Andree Toonk</description>
	<lastBuildDate>Mon, 28 Jun 2010 22:41:37 +0000</lastBuildDate>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.0</generator>
	<item>
		<title>By: Andree</title>
		<link>http://www.toonk.nl/blog/?p=522&#038;cpage=1#comment-8607</link>
		<dc:creator>Andree</dc:creator>
		<pubDate>Wed, 13 Jan 2010 06:39:15 +0000</pubDate>
		<guid isPermaLink="false">http://www.toonk.nl/blog/?p=522#comment-8607</guid>
		<description>It seems that routers running 7.4 or earlier are not affected. 
Tests with 7.4, 7.2R4.2 and 5.0.0r8.0 did not result in crashes.</description>
		<content:encoded><![CDATA[<p>It seems that routers running 7.4 or earlier are not affected.<br />
Tests with 7.4, 7.2R4.2 and 5.0.0r8.0 did not result in crashes.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: JeDraco</title>
		<link>http://www.toonk.nl/blog/?p=522&#038;cpage=1#comment-8572</link>
		<dc:creator>JeDraco</dc:creator>
		<pubDate>Mon, 11 Jan 2010 03:47:06 +0000</pubDate>
		<guid isPermaLink="false">http://www.toonk.nl/blog/?p=522#comment-8572</guid>
		<description>JunOS firewall can&#039;t identify specific malicious packets, or spoofed ones.  What&#039;s bothersome is the security bulletin from Juniper seemed to imply firewall could not help at all.

If your routers utilize protections such as TTL security and uRPF to prevent IP spoofing, and only accept TCP packets addressed to RE, from proper sources, then the firewall filter could be 98% effective if you have analyzed your situation carefully.

Some network operators who already utilize these mitigation strategies fully, may have been mislead into thinking the issue effected them more seriously than it does.

Some juniper customers may have created unnecessary service-effecting outages for their clients, to perform an emergency upgrade on reliance of the  Juniper bulletin  implying firewall was not a usable workaround in any case.

That could have been delayed until a proper maintenance window,  or until proper notice could be delivered.

In other words,  Juniper should have been more upfront and disclosed more information regarding WHY firewall cannot be used as an effective workaround.</description>
		<content:encoded><![CDATA[<p>JunOS firewall can&#8217;t identify specific malicious packets, or spoofed ones.  What&#8217;s bothersome is the security bulletin from Juniper seemed to imply firewall could not help at all.</p>
<p>If your routers utilize protections such as TTL security and uRPF to prevent IP spoofing, and only accept TCP packets addressed to RE, from proper sources, then the firewall filter could be 98% effective if you have analyzed your situation carefully.</p>
<p>Some network operators who already utilize these mitigation strategies fully, may have been mislead into thinking the issue effected them more seriously than it does.</p>
<p>Some juniper customers may have created unnecessary service-effecting outages for their clients, to perform an emergency upgrade on reliance of the  Juniper bulletin  implying firewall was not a usable workaround in any case.</p>
<p>That could have been delayed until a proper maintenance window,  or until proper notice could be delivered.</p>
<p>In other words,  Juniper should have been more upfront and disclosed more information regarding WHY firewall cannot be used as an effective workaround.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Prefect</title>
		<link>http://www.toonk.nl/blog/?p=522&#038;cpage=1#comment-8570</link>
		<dc:creator>Prefect</dc:creator>
		<pubDate>Mon, 11 Jan 2010 02:44:54 +0000</pubDate>
		<guid isPermaLink="false">http://www.toonk.nl/blog/?p=522#comment-8570</guid>
		<description>Nice video, this topic needs to continue to be advanced (actually would like to see some analysis of the Juniper response now that the news that the exploit is in the wild and patch out is over).

On our end, we repeated the assertion from Juniper in the bulletin (citing Juniper) that such filtering would not be totally effective (our primary purpose being to publish our confirmation that this was an exploitable problem, and the header value not hard to find quickly so people could consider this in their risk evaluation on patching quickly). To that end, the second link to our blog in the post as a resource needing refuting is probably not appropriate 4 days after the fact.

We continue to think and advise that reliance on such defenses (while most should be in place regardless) is not a substitute for quick analysis and patching of this problem.</description>
		<content:encoded><![CDATA[<p>Nice video, this topic needs to continue to be advanced (actually would like to see some analysis of the Juniper response now that the news that the exploit is in the wild and patch out is over).</p>
<p>On our end, we repeated the assertion from Juniper in the bulletin (citing Juniper) that such filtering would not be totally effective (our primary purpose being to publish our confirmation that this was an exploitable problem, and the header value not hard to find quickly so people could consider this in their risk evaluation on patching quickly). To that end, the second link to our blog in the post as a resource needing refuting is probably not appropriate 4 days after the fact.</p>
<p>We continue to think and advise that reliance on such defenses (while most should be in place regardless) is not a substitute for quick analysis and patching of this problem.</p>
]]></content:encoded>
	</item>
</channel>
</rss>
