<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	>
<channel>
	<title>Comments on: Breaking:  Now Patch Your Firewalls Because the DNS Patch Won&#8217;t Work With Leading Firewalls</title>
	<atom:link href="http://broaddev.com/2008/07/29/breaking-firewalls-wont-work-with-the-patch-cisco-firewalls-affected/feed/" rel="self" type="application/rss+xml" />
	<link>http://broaddev.com/2008/07/29/breaking-firewalls-wont-work-with-the-patch-cisco-firewalls-affected/</link>
	<description></description>
	<pubDate>Tue, 16 Mar 2010 12:09:54 +0000</pubDate>
	<generator>http://wordpress.org/?v=2.5.1</generator>
		<item>
		<title>By: BroadDev - Unified Communications, Virtualization, Security, and Web 2.0 &#187; Timeline of DNS Story - It&#8217;s Getting Out of Hand - Ok - So What&#8217;s the Solution</title>
		<link>http://broaddev.com/2008/07/29/breaking-firewalls-wont-work-with-the-patch-cisco-firewalls-affected/#comment-381</link>
		<dc:creator>BroadDev - Unified Communications, Virtualization, Security, and Web 2.0 &#187; Timeline of DNS Story - It&#8217;s Getting Out of Hand - Ok - So What&#8217;s the Solution</dc:creator>
		<pubDate>Thu, 07 Aug 2008 18:53:55 +0000</pubDate>
		<guid isPermaLink="false">http://broaddev.com/?p=117#comment-381</guid>
		<description>[...] July 29, 2008 - Breaking News:  Now Patch Your Firewalls Because the DSN Patch Won&#8217;t Work Wit... [...]</description>
		<content:encoded><![CDATA[<p>[...] July 29, 2008 - Breaking News:  Now Patch Your Firewalls Because the DSN Patch Won&#8217;t Work Wit&#8230; [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: BroadDev - Unified Communications, Virtualization, Security, and Web 2.0 &#187; Kaminsky&#8217;s DNS Exploit Exposes Internet Core Challenge</title>
		<link>http://broaddev.com/2008/07/29/breaking-firewalls-wont-work-with-the-patch-cisco-firewalls-affected/#comment-355</link>
		<dc:creator>BroadDev - Unified Communications, Virtualization, Security, and Web 2.0 &#187; Kaminsky&#8217;s DNS Exploit Exposes Internet Core Challenge</dc:creator>
		<pubDate>Fri, 01 Aug 2008 01:41:42 +0000</pubDate>
		<guid isPermaLink="false">http://broaddev.com/?p=117#comment-355</guid>
		<description>[...] the story gets worse. Recent news suggests that firewalls may have been impacted, including those widely deployed to protect servers. Compatibility issues between the DNS vulnerability patch and firewalls have [...]</description>
		<content:encoded><![CDATA[<p>[...] the story gets worse. Recent news suggests that firewalls may have been impacted, including those widely deployed to protect servers. Compatibility issues between the DNS vulnerability patch and firewalls have [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Kaminsky’s DNS Exploit Exposes the Internet’s Core Challenge &#171; ARCHIMEDIUS</title>
		<link>http://broaddev.com/2008/07/29/breaking-firewalls-wont-work-with-the-patch-cisco-firewalls-affected/#comment-354</link>
		<dc:creator>Kaminsky’s DNS Exploit Exposes the Internet’s Core Challenge &#171; ARCHIMEDIUS</dc:creator>
		<pubDate>Thu, 31 Jul 2008 19:42:23 +0000</pubDate>
		<guid isPermaLink="false">http://broaddev.com/?p=117#comment-354</guid>
		<description>[...] the story gets worse.  Recent news suggests that firewalls may have been impacted, including those widely deployed to protect servers.  Compatibility issues between the DNS vulnerability patch and firewalls have [...]</description>
		<content:encoded><![CDATA[<p>[...] the story gets worse.  Recent news suggests that firewalls may have been impacted, including those widely deployed to protect servers.  Compatibility issues between the DNS vulnerability patch and firewalls have [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: BroadDev - Unified Communications, Virtualization, Security, and Web 2.0 &#187; DNS SUCKS - Ok I Said It - Now What - Talk to Trusted Sources Until PAT mode is Fixed</title>
		<link>http://broaddev.com/2008/07/29/breaking-firewalls-wont-work-with-the-patch-cisco-firewalls-affected/#comment-352</link>
		<dc:creator>BroadDev - Unified Communications, Virtualization, Security, and Web 2.0 &#187; DNS SUCKS - Ok I Said It - Now What - Talk to Trusted Sources Until PAT mode is Fixed</dc:creator>
		<pubDate>Wed, 30 Jul 2008 22:19:13 +0000</pubDate>
		<guid isPermaLink="false">http://broaddev.com/?p=117#comment-352</guid>
		<description>[...] I blogged yesterday that Cisco firewalls were affected and rendered the DNS patch useless. Well that was true BUT it&#8217;s not just Cisco - it&#8217;s everyone. There is a bigger picture. DNS sucks. There is too much legacy and critical infrastructure that is more important then some sort of url rewrite and a hacking of a 16 bit port translation (or PAT - Port Address Translation).  It&#8217;s called &#8216;industrial strength&#8217; software.  Companies like Infoblox and Nominum have growing businesses because they took DNS and scaled it with security.  Can vendors do more with it or has it reached it&#8217;s peak?  Either way this DNS shit is a problem for IT and network operators.   It seem like they are chasing too many holes out there.  Is it time to rip and replace.  I&#8217;ll keep my official opinion to myself. [...]</description>
		<content:encoded><![CDATA[<p>[...] I blogged yesterday that Cisco firewalls were affected and rendered the DNS patch useless. Well that was true BUT it&#8217;s not just Cisco - it&#8217;s everyone. There is a bigger picture. DNS sucks. There is too much legacy and critical infrastructure that is more important then some sort of url rewrite and a hacking of a 16 bit port translation (or PAT - Port Address Translation).  It&#8217;s called &#8216;industrial strength&#8217; software.  Companies like Infoblox and Nominum have growing businesses because they took DNS and scaled it with security.  Can vendors do more with it or has it reached it&#8217;s peak?  Either way this DNS shit is a problem for IT and network operators.   It seem like they are chasing too many holes out there.  Is it time to rip and replace.  I&#8217;ll keep my official opinion to myself. [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Jimmy</title>
		<link>http://broaddev.com/2008/07/29/breaking-firewalls-wont-work-with-the-patch-cisco-firewalls-affected/#comment-345</link>
		<dc:creator>Jimmy</dc:creator>
		<pubDate>Wed, 30 Jul 2008 01:44:10 +0000</pubDate>
		<guid isPermaLink="false">http://broaddev.com/?p=117#comment-345</guid>
		<description>John
Thanks for posting this.  Not many people understand that this is a big problem.  Patches are great but knowing the implementation consequences is important.  Nomimum has a great solution to this.  

Looking forward to hearing more about how this develops</description>
		<content:encoded><![CDATA[<p>John<br />
Thanks for posting this.  Not many people understand that this is a big problem.  Patches are great but knowing the implementation consequences is important.  Nomimum has a great solution to this.  </p>
<p>Looking forward to hearing more about how this develops</p>
]]></content:encoded>
	</item>
</channel>
</rss>
