SunScreen EFS Release 3.0 Installation Guide

Operating the Firewall in Stealth Mode

Operate SunScreen EFS 3.0 in stealth mode if you do not need routing functions, or if you want to decrease possibilities for attacks. In stealth mode, SunScreen EFS 3.0 acts much like a bridge in that no IP interfaces are exposed to the public or private network, and packets are transparently passed through the Screen. While operating in this mode, the SunScreen cannot be attacked through any means other than a denial of service attack, and cannot be seen or detected through traceroute or similar network tools.

Key differences when operating SunScreen EFS in stealth, rather than routing, mode:

SunScreen EFS 3.0 allows the use of SPF-style stealth network interfaces. But it does not operate in the exact same fashion as a SunScreen SPF-200 does. Some notable differences between operating SunScreen EFS 3.0 in stealth mode, from the SunScreen SPF-200, are: