[6bone] Commercial IPv6-ready firewall products?

David Carmean dlc-6bone@halibut.com
Thu, 19 Sep 2002 08:59:45 -0700


On Fri, Sep 20, 2002 at 12:44:14AM +0900, Jun-ichiro itojun Hagino wrote:
> >On Thu, Sep 19, 2002 at 07:32:03AM -0700, David Carmean wrote:
> >> Are there yet any commercially-supported firewall products with support 
> >> for IPv6, both tunnelled and native?  
> >Checkpoint has announced IPv6 support for "September 2002" (search for IPv6
> >on www.checkpoint.com for the press release).  It's not there yet, though.
> >Cisco PIX and Netscreen are scheduled for "Q1/2003"...
> 
> 	not a commercial product, but OpenBSD PF works great.

Absolutely, although I prefer Darren Reed's original IPF, on 
FreeBSD.  I'm just looking for alternatives in case the manglers 
refuse to use something we can't pay someone they can blame^w^w^w
to support it.

W.R.T. the Juniper and Cisco ACL suggestions... at the very least 
I will insist on a stateful packet filter, if not stateful 
inspection.