× NETGEAR is aware of a growing number of phone and online scams. To learn how to stay safe click here.
Announcements

Polls
What is your Experience with NETGEAR Insight cloud management?
Top Contributors
0 Kudos

Firewall enhancement

Re: orbipro sxk80 WiFi 6

 

Can the firewall be enhanced to filter cookies similar to the prosafe?

 

Will any gateway incorporate the next content disarm and reconstruction technique or the positive selection technology that removes potential active threat elements?

explained here:

https://votiro.com/resource-center/what-is-cdr-positive-selection/ 

3 Comments
schumaku
Guru

Considering Web traffic (including cookies) transport is end2end encrypted nowadays, being in https (in IP or QUIC transport protocol), .... how do you expect the in-line device (router here) is breaking the encryption to gain control over the cookies?

 

Even harder for the active threat elements: You need not just to break the secured channel, much more you have to bring all the file traffic over a server or proxy (as the linked vendor does of course) or deal with these files on the end point, so the downloads are becoming available outside of the end2end encrypted channel. Needless to say, especially the proxy approach can and will break application and App connectivity ....

Orbipro1
Aspirant

Schumaku
thank you for your answer.  Just wishful thinking.  Maybe another way to affect cookies and other threats like stegenography.

 

Orbipro1
Aspirant

Schumaku

 

i agree , prefer direct or indirect communication if its ssecure, anomous, private address, maybe encryopted sni will help. Client side credentials; FIDO standard of authentication for access to and control of network, wifi and router. Geofenced access control for devices near and point or endpoint.

 

Exactly why i prefer a gateway endpoint access hardware that can affect the vulnerability. Preferably a device that resolves these issues without additional hardware.

 

i am not sure if the apps to app will be sufficient with or without strong devices and private channels.