[fw-wiz] Evolution of Firewalls

skpoo_at_pacific.net.sg
Date: 03/04/04

  • Next message: Brian Ford: "Re: [fw-wiz] PIX to PIX IPSec Tunnel Through a PIX"
    To: <firewall-wizards@honor.icsalabs.com>
    Date: Thu, 4 Mar 2004 23:56:12 +0800
    
    

    Hi, I am currently evaluating several types of firewalls for the company.

    Our team is currently debating if Stateful Deep Inspection firewall is going be the new technology to replace the Application Proxies firewall which deem to be most secure currently.

    I personally feel that Deep Inspection firewall is less reliable as we know that it only blocks what is known to be bad. This seems to be less effective and become an never-ending arm race where Deep Inspectioin firewall requires the most updated bad list all the time.

    On the other hand, Application Proxies firewall only allows what is known to be good. This makes the defence become more effective as we know good things do not change as frequently as bad things.

    Any input would be very much appreciated.

    Kang
     

    _______________________________________________
    firewall-wizards mailing list
    firewall-wizards@honor.icsalabs.com
    http://honor.icsalabs.com/mailman/listinfo/firewall-wizards


  • Next message: Brian Ford: "Re: [fw-wiz] PIX to PIX IPSec Tunnel Through a PIX"

    Relevant Pages

    • Re: [fw-wiz] Evolution of Firewalls
      ... ALG Support (There are some applications that don't work ... Analyze your security requirements and make sure that firewall satisfies ... >Our team is currently debating if Stateful Deep Inspection firewall is ... Application Proxies firewall only allows what is known ...
      (Firewall-Wizards)
    • Re: [fw-wiz] Evolution of Firewalls
      ... Our team is currently debating if Stateful Deep Inspection firewall is ... >going be the new technology to replace the Application Proxies firewall ... >which deem to be most secure currently. ...
      (Firewall-Wizards)
    • Recommendations
      ... I am currently debating what type of firewall to use at my home. ... first a NAT/Firewall as an internet gateway and that is my main concern. ...
      (comp.security.firewalls)