FirewallWizards
[Top] [All Lists]

Re: [fw-wiz] IP Ranges

To: Firewall Wizards Security Mailing List <firewall-wizards@listserv.icsalabs.com>
Subject: Re: [fw-wiz] IP Ranges
From: Sergio Pozo Hidalgo <sergio@lsi.us.es>
Date: Fri, 30 Mar 2007 16:51:36 +0200
Delivered-to: sp-com-lists@consult.net
Delivered-to: fwwizards-list2@consult.net
Delivered-to: firewall-wizards@listserv.cybertrust.com
In-reply-to: <92db0b590703291351n3e02f5aeg498022a6dc1db47f@mail.gmail.com>
List-archive: <https://listserv.icsalabs.com/pipermail/firewall-wizards>
List-help: <mailto:firewall-wizards-request@listserv.icsalabs.com?subject=help>
List-id: Firewall Wizards Security Mailing List <firewall-wizards.listserv.icsalabs.com>
List-post: <mailto:firewall-wizards@listserv.icsalabs.com>
List-subscribe: <https://listserv.icsalabs.com/mailman/listinfo/firewall-wizards>, <mailto:firewall-wizards-request@listserv.icsalabs.com?subject=subscribe>
List-unsubscribe: <https://listserv.icsalabs.com/mailman/listinfo/firewall-wizards>, <mailto:firewall-wizards-request@listserv.icsalabs.com?subject=unsubscribe>
References: <4607F5B6.3040506@lsi.us.es> <6c7b22150703271248t1e252622jabbfae188e7e6749@mail.gmail.com> <AA8E89377DCB1C498CF19E343CA49D8E105ECD@NYEXCHSVR01.texpac.com> <92db0b590703291351n3e02f5aeg498022a6dc1db47f@mail.gmail.com>
Reply-to: Firewall Wizards Security Mailing List <firewall-wizards@listserv.icsalabs.com>
Sender: firewall-wizards-bounces@listserv.icsalabs.com
User-agent: Thunderbird 1.5.0.10 (Windows/20070221)
Security Guy escribió:
> specifically regarding PIX
> 
> Object groups do make ACL management a whole lot easier, but you're
> still stuck specifying hosts or contiguous networks within the group,
> you can't just put in a range like 192.168.10.15-28 that doesn't
> summarize nicely.

Mmmm. I was thinking and experimenting with several subnet calculators,
and I conclude that the only ranges that can be specifyed are of the
kind IP/CIDR, because if you specify something like 192.168.1.20-30 it
can mean that range of ten IPs (in this case, in other cases it can be
several IPs), or it can mean:
192.168.1.20/255.255.255.252
192.168.1.24/255.255.255.252
192.168.1.28/255.255.255.254
192.168.1.30/255.255.255.255

which aren't in the same network range... In any case, you cannot
specify which of the two options you want, and IPTables documentation
doesn't say it.
I think that this is one of the reasons why the ip-range option is not a
very useful one, and is only implemented (I suppose) in IPTables 2.4 and
2.6.

-Sergio
_______________________________________________
firewall-wizards mailing list
firewall-wizards@listserv.icsalabs.com
https://listserv.icsalabs.com/mailman/listinfo/firewall-wizards

<Prev in Thread] Current Thread [Next in Thread>