Re: [fw-wiz] Evolution of Firewalls

From: Frederick M Avolio (fred_at_avolio.com)
Date: 03/08/04

  • Next message: Scott C. Kennedy: "[fw-wiz] Problems logging deny's on Cisco Routers?"
    To: Dave Piscitello <dave@corecom.com>, <skpoo@pacific.net.sg>, <firewall-wizards@honor.icsalabs.com>
    Date: Mon, 08 Mar 2004 15:14:46 -0500
    
    

    At 02:37 PM 3/8/2004 -0500, Dave Piscitello wrote:
    >Lots of names for the same security functionality: examining application
    >headers and application data streams for attacks and blocking them. You
    >can and some vendors still do this using proxy architecture, while some
    >use the same stateful packet inspecting methods they used to examine
    >network protocol headers.

    well, yeah but not really. That is the problem. All different names for
    slightly different ways of doing things. The the devil is in the
    difference. But some people have lost those differences in the marketing
    noise, if they ever understood the differences.

    >The most secure firewall? Probably has less to do with proxy vs. stateful
    >inspection than policy, implementation/configuration, and the admin at the
    >policy console.

    I disagree. Both are important. The greatest policy then only gives you as
    much security as your security mechanisms will allow.

    Fred

    _______________________________________________
    firewall-wizards mailing list
    firewall-wizards@honor.icsalabs.com
    http://honor.icsalabs.com/mailman/listinfo/firewall-wizards


  • Next message: Scott C. Kennedy: "[fw-wiz] Problems logging deny's on Cisco Routers?"

    Relevant Pages

    • Fwd: Oh Dear, Where to start?!
      ... It seems to me you need two things: an organizational policy, ... finish college and break into the real world of computer security. ... experience in the field of network security and policy ... updates, driver updates, and recommended updates. ...
      (Security-Basics)
    • RE: [fw-wiz] PIX vs Checkpoint vs Sonicwall vs Netscreen - comme nts?
      ... All NetScreen appliances rely on custom-designed ASICs (Application ... Specific Integrated Circuits) for security policy enforcement. ... supports a finite number of "rules" or "policies". ...
      (Firewall-Wizards)
    • RE: Cant set Local Security policies. They fail to save
      ... predefined Security Template on SBS 2003 to restore security groups ... run "gpupdate.exe /force" under command prompt to force the policy ... reboot the Server to test. ... and then logon to client computer to test if user can save system logs. ...
      (microsoft.public.windows.server.sbs)
    • RE: [fw-wiz] PIX vs Checkpoint vs Sonicwall vs Netscreen - comme nts?
      ... The report you cite is CheckPoint originated and deals with older NetScreen ... All NetScreen appliances rely on custom-designed ASICs (Application ... Specific Integrated Circuits) for security policy enforcement. ...
      (Firewall-Wizards)
    • Re: No Shut Down or Restart for Domain Admins
      ... run rsop.msc from your DC and check which policy is responsible to this. ... I have created a group policy in a development network and imported it ... NT AUTHORITY\Authenticated Users Read (from Security Filtering) No ... Enforce user logon restrictions Enabled ...
      (microsoft.public.windows.server.active_directory)