<?xml version='1.0' encoding='UTF-8'?><?xml-stylesheet href="http://www.blogger.com/styles/atom.css" type="text/css"?><feed xmlns='http://www.w3.org/2005/Atom' xmlns:openSearch='http://a9.com/-/spec/opensearchrss/1.0/'><id>tag:blogger.com,1999:blog-7997313029981170997.post3958991155974112436..comments</id><updated>2010-08-17T12:05:12.477-04:00</updated><category term='mobile'/><category term='Fedora'/><category term='postgres'/><category term='tools'/><category term='sysadmin'/><category term='pentaho'/><category term='community'/><category term='hosting'/><category term='analytics'/><category term='SELinux'/><category term='perl data-structures json'/><category term='redhat'/><category term='audio'/><category term='travel'/><category term='css'/><category term='git'/><category term='tips'/><category term='nginx'/><category term='Spree'/><category term='cakephp'/><category term='email'/><category term='nosql'/><category term='social-networking'/><category term='unicode'/><category term='performance'/><category term='piggybak'/><category term='eye-candy'/><category term='reporting'/><category term='thrift'/><category term='facebook'/><category term='visualization'/><category term='openbsd'/><category term='mysql'/><category term='scalability'/><category term='riak'/><category term='security'/><category term='CentOS'/><category term='graphics'/><category term='cucumber'/><category term='rvm'/><category term='cloud'/><category term='django'/><category term='remote-work'/><category term='networking'/><category term='wordpress'/><category term='perlbrew'/><category term='optimization'/><category term='book review'/><category term='dropbox'/><category term='sinatra'/><category term='design'/><category term='mp3'/><category term='ruby-and-ruby-on-rails'/><category term='testing'/><category term='open-source'/><category term='json'/><category term='ruby'/><category term='yui'/><category term='virtualization'/><category term='COTS'/><category term='Camps'/><category term='javascript'/><category term='workflow'/><category term='sponsorship'/><category term='perl'/><category term='messaging'/><category term='environment'/><category term='gnu'/><category term='lua'/><category term='rpm'/><category term='browsers'/><category term='configuration-management'/><category term='python'/><category term='ecommerce'/><category term='Conference'/><category term='voldemort'/><category term='image'/><category term='jasper'/><category term='clients'/><category term='dbdpg'/><category term='Android'/><category term='database'/><category term='version-control'/><category term='linux'/><category term='USPS'/><category term='data-warehouse'/><category term='openafs'/><category term='cassandra'/><category term='mondaylinks'/><category term='php'/><category term='Debian'/><category term='monitoring'/><category term='liquid-galaxy'/><category term='audit'/><category term='Bucardo'/><category term='Java'/><category term='mongodb'/><category term='API'/><category term='seo'/><category term='SeniorNet'/><category term='company'/><category term='jquery'/><category term='jobs'/><category term='sql'/><category term='search'/><category term='Ubuntu'/><category term='Interchange'/><category term='caching'/><category term='ipv6'/><title type='text'>Comments on End Point Blog: Cisco PIX mangled packets and iptables state track...</title><link rel='http://schemas.google.com/g/2005#feed' type='application/atom+xml' href='http://blog.endpoint.com/feeds/3958991155974112436/comments/default'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/7997313029981170997/3958991155974112436/comments/default'/><link rel='alternate' type='text/html' href='http://blog.endpoint.com/2009/12/cisco-pix-mangled-packets-and-iptables.html'/><author><name>Jon Jensen</name><uri>http://www.blogger.com/profile/18273388885281263476</uri><email>noreply@blogger.com</email><gd:image xmlns:gd='http://schemas.google.com/g/2005' rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='25' src='http://bp3.blogger.com/_rFXHDrokbpE/SJHpPosaIQI/AAAAAAAAAAM/GnqeZuLItOA/S220/jon1.png'/></author><generator version='7.00' uri='http://www.blogger.com'>Blogger</generator><openSearch:totalResults>4</openSearch:totalResults><openSearch:startIndex>1</openSearch:startIndex><openSearch:itemsPerPage>25</openSearch:itemsPerPage><entry><id>tag:blogger.com,1999:blog-7997313029981170997.post-4930471637485226894</id><published>2010-08-17T12:05:12.477-04:00</published><updated>2010-08-17T12:05:12.477-04:00</updated><title type='text'>I&amp;#39;m sure it must be allowing some invalid pack...</title><content type='html'>I&amp;#39;m sure it must be allowing some invalid packets, though I don&amp;#39;t know the details. I&amp;#39;m not very worried about it because the Linux networking stack probably just ignores them.&lt;br /&gt;&lt;br /&gt;Yes, it should be fixed on the Cisco box, but good luck getting Cisco to do that. Apparently others have tried. :)</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/7997313029981170997/3958991155974112436/comments/default/4930471637485226894'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/7997313029981170997/3958991155974112436/comments/default/4930471637485226894'/><link rel='alternate' type='text/html' href='http://blog.endpoint.com/2009/12/cisco-pix-mangled-packets-and-iptables.html?showComment=1282061112477#c4930471637485226894' title=''/><author><name>Jon Jensen</name><uri>http://www.blogger.com/profile/18273388885281263476</uri><email>noreply@blogger.com</email><gd:image xmlns:gd='http://schemas.google.com/g/2005' rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='25' src='http://bp3.blogger.com/_rFXHDrokbpE/SJHpPosaIQI/AAAAAAAAAAM/GnqeZuLItOA/S220/jon1.png'/></author><thr:in-reply-to xmlns:thr='http://purl.org/syndication/thread/1.0' href='http://blog.endpoint.com/2009/12/cisco-pix-mangled-packets-and-iptables.html' ref='tag:blogger.com,1999:blog-7997313029981170997.post-3958991155974112436' source='http://www.blogger.com/feeds/7997313029981170997/posts/default/3958991155974112436' type='text/html'/><gd:extendedProperty xmlns:gd='http://schemas.google.com/g/2005' name='blogger.itemClass' value='pid-932649491'/></entry><entry><id>tag:blogger.com,1999:blog-7997313029981170997.post-3326545847219400999</id><published>2010-08-16T03:23:54.809-04:00</published><updated>2010-08-16T03:23:54.809-04:00</updated><title type='text'>Do you know if this has any impact on security, in...</title><content type='html'>Do you know if this has any impact on security, in terms of invalid packet attacks? This &amp;#39;be liberal&amp;#39; sounds like it allows certain types of invalid packets.&lt;br /&gt;&lt;br /&gt;Also I think this should be fixed on the cisco, thats the box giving out the &amp;#39;invalid&amp;#39; packets? (mind you I have zero experience with cisco boxes, its easier to say than do ;) ). &lt;br /&gt;&lt;br /&gt;Thanks for the post though, you&amp;#39;ve put it in easy to understand terms!</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/7997313029981170997/3958991155974112436/comments/default/3326545847219400999'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/7997313029981170997/3958991155974112436/comments/default/3326545847219400999'/><link rel='alternate' type='text/html' href='http://blog.endpoint.com/2009/12/cisco-pix-mangled-packets-and-iptables.html?showComment=1281943434809#c3326545847219400999' title=''/><author><name>Big dog</name><email>noreply@blogger.com</email><gd:image xmlns:gd='http://schemas.google.com/g/2005' rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img1.blogblog.com/img/blank.gif'/></author><thr:in-reply-to xmlns:thr='http://purl.org/syndication/thread/1.0' href='http://blog.endpoint.com/2009/12/cisco-pix-mangled-packets-and-iptables.html' ref='tag:blogger.com,1999:blog-7997313029981170997.post-3958991155974112436' source='http://www.blogger.com/feeds/7997313029981170997/posts/default/3958991155974112436' type='text/html'/><gd:extendedProperty xmlns:gd='http://schemas.google.com/g/2005' name='blogger.itemClass' value='pid-447926684'/></entry><entry><id>tag:blogger.com,1999:blog-7997313029981170997.post-6463943265631835607</id><published>2010-04-07T17:14:17.703-04:00</published><updated>2010-04-07T17:14:17.703-04:00</updated><title type='text'>Glad to hear it helped, Pat!</title><content type='html'>Glad to hear it helped, Pat!</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/7997313029981170997/3958991155974112436/comments/default/6463943265631835607'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/7997313029981170997/3958991155974112436/comments/default/6463943265631835607'/><link rel='alternate' type='text/html' href='http://blog.endpoint.com/2009/12/cisco-pix-mangled-packets-and-iptables.html?showComment=1270674857703#c6463943265631835607' title=''/><author><name>Jon Jensen</name><uri>http://www.blogger.com/profile/18273388885281263476</uri><email>noreply@blogger.com</email><gd:image xmlns:gd='http://schemas.google.com/g/2005' rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='25' src='http://bp3.blogger.com/_rFXHDrokbpE/SJHpPosaIQI/AAAAAAAAAAM/GnqeZuLItOA/S220/jon1.png'/></author><thr:in-reply-to xmlns:thr='http://purl.org/syndication/thread/1.0' href='http://blog.endpoint.com/2009/12/cisco-pix-mangled-packets-and-iptables.html' ref='tag:blogger.com,1999:blog-7997313029981170997.post-3958991155974112436' source='http://www.blogger.com/feeds/7997313029981170997/posts/default/3958991155974112436' type='text/html'/><gd:extendedProperty xmlns:gd='http://schemas.google.com/g/2005' name='blogger.itemClass' value='pid-932649491'/></entry><entry><id>tag:blogger.com,1999:blog-7997313029981170997.post-8689102949255860790</id><published>2010-04-07T15:59:36.000-04:00</published><updated>2010-04-07T15:59:36.000-04:00</updated><title type='text'>Woah.  This finally resolved a problem we were hav...</title><content type='html'>Woah.  This finally resolved a problem we were having with an otherwise flawless Linux firewall box I&amp;#39;ve been using in my lab.&lt;br /&gt;&lt;br /&gt;Thanks for putting this out there.</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/7997313029981170997/3958991155974112436/comments/default/8689102949255860790'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/7997313029981170997/3958991155974112436/comments/default/8689102949255860790'/><link rel='alternate' type='text/html' href='http://blog.endpoint.com/2009/12/cisco-pix-mangled-packets-and-iptables.html?showComment=1270670376000#c8689102949255860790' title=''/><author><name>Pat Morin</name><uri>http://www.blogger.com/profile/06328185728688465505</uri><email>noreply@blogger.com</email><gd:image xmlns:gd='http://schemas.google.com/g/2005' rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='24' src='http://2.bp.blogspot.com/_WZ5utiUQCAo/SOqlMeesIcI/AAAAAAAAARU/pozLp7ObjKA/s1600-R/skocjan.jpg'/></author><thr:in-reply-to xmlns:thr='http://purl.org/syndication/thread/1.0' href='http://blog.endpoint.com/2009/12/cisco-pix-mangled-packets-and-iptables.html' ref='tag:blogger.com,1999:blog-7997313029981170997.post-3958991155974112436' source='http://www.blogger.com/feeds/7997313029981170997/posts/default/3958991155974112436' type='text/html'/><gd:extendedProperty xmlns:gd='http://schemas.google.com/g/2005' name='blogger.itemClass' value='pid-2131353279'/></entry></feed>
