[fw-wiz] Firewalls v. Router ACLs

WhiteHat_at_btclick.com
Date: 12/11/03

  • Next message: edp: "R: [fw-wiz] PIX DMZ inter-access via outside IP address"
    To: firewall-wizards@nfr.net
    Date: Thu, 11 Dec 2003 14:48:37 -0000
    
    

    Hi All,

    I hope this is the appropriate forum for my question, and I apologise if not but I am
    looking for information and would appreciate any help.

    I currently work for a department in a large company. Our department has always
    used firewalls (CheckPoint on Nokia) to protect our part of the network from network
    worms and other 'nasty stuff' on the rest of the network. Our view is that this
    'segmentation' makes it easier to contain any infection. This strategy has been almost
    100% successful and we have not been impacted by the numerous network-borne
    worms etc. over the years.

    We are now being pressurised to remove the firewalls by the rest of the company.
    The argument is that using well defined ACLs (with a default 'deny all' statement at
    the end) on the the Cisco WAN routers would have the same effect as the current
    firewalls. A secondary argument is cost - the router is seen as a one-off purchase
    while the Checkpoint software has an annual licence cost. I am trying to gather
    evidence of the pros and cons of this approach.

    In particular, I am concerned about:
    - performance - will the routers be able to manage this as they are designed to route
    traffic, not stop it?
    - logging - what would be the best way to consolidate the router logs for analysis etc.?
    - incident management - if a router is being hammered by a network worm (e.g.
    MSBlaster/LovSan), how easy will it be to manage to make any emergency changes
    necessary? Won't it be so busy dropping packets it becomes impossible to make the
    change?
    - future capability - I see the AI-type technologies evolving in firewalls as providing a
    useful IPS-type functionality in the future. This will allow more open rule sets but
    automated protection if things go wrong. Has anyone successfully implemented this
    yet? Can this be enough justification to keep the firewalls?

    Does anyone know of any case studies or horror stories of organisations that have
    attempted this?

    Has anyone had success doing this that they would be willing to share?

    Thanks in advance for any help.

    Regards
            Richard

    _______________________________________________
    firewall-wizards mailing list
    firewall-wizards@honor.icsalabs.com
    http://honor.icsalabs.com/mailman/listinfo/firewall-wizards


  • Next message: edp: "R: [fw-wiz] PIX DMZ inter-access via outside IP address"

    Relevant Pages

    • RE: [fw-wiz] Firewalls v. Router ACLs
      ... people to take in consideration in network design and layout. ... here and the old firewalls list often emphasized an approach that avoided ... The logging alert features alone turn this layer into a IDS as ... > An appropriately sized router will not have any performance problems. ...
      (Firewall-Wizards)
    • Re: [fw-wiz] Firewall routing thought...
      ... networks that the firewalls are protecting, ... and let the router sort out what networks are ... >>Your network layout isn't really clear from your email, ... >>you make a change in broadcast domains, the router is going to be involved. ...
      (Firewall-Wizards)
    • RE: HSRP with load balancing on a Cisco IOS based firewall
      ... Can I implement MHSRP across IOS based firewalls on Ciso routers? ... Split the network behind the Firewall into subnets say Network A and network ... Network A has router X as its primery and router Y as its secondary. ... My prelimnary research on HSRP gives me the understanding that in an HSRP ...
      (Security-Basics)
    • Re: local networking and firewalls
      ... you will need to open the appropriate ports in the firewalls on ... As for whether your router is an adequate firewall is hard to say. ... All computers, the printer, and the DSL modem connect ... > The network only functions if I turn off all Firewalls on the individual ...
      (microsoft.public.windowsxp.network_web)
    • Re: Unable to ping other local IP XP Pro PCs.
      ... If you have any non-Microsoft firewalls in the mix, ... them for network access. ... Both computers can ping the router with 4 successful replies. ...
      (microsoft.public.windowsxp.network_web)