Re: [fw-wiz] Re: firewall-wizards digest, Vol 1 #1229 - 18 msgs

From: Dale W. Carder (dwcarder_at_doit.wisc.edu)
Date: 03/10/04

  • Next message: Devdas Bhagat: "Re: [fw-wiz] Evolution of Firewalls"
    To: Bill Van Emburg <bve@quadrix.com>
    Date: Tue, 09 Mar 2004 17:30:51 -0600
    
    

    I am a vlan bigot. If that offends you, read no further! :-)

    On Mar 7, 2004, at 11:15 AM, Bill Van Emburg wrote:
    > I, personally, am a very big fan of separate physical switches per
    > segment.
    > ...
    > protects you against the *next* bug to be found in your switch
    > vendor's VLAN software (because ALL CODE HAS BUGS ... security 101,
    > right?)
    > ...
    > is easier to maintain

    So now you have to update the firmware and maintain the configurations
    on 'n' many separate switches instead only a few? I believe that less
    to maintain is easier.

    > (how many spare 6500s do you have in *your* infrastructure?)

    14. High Availability was a design requirement.

    > and allows for easy separation of control (do *you* have a good way to
    > have separate VLANs administered by different sysadms?).

    We have a few hundred vlans, most of each with it's own sysadmin, and
    each with its own security domain.

    > From a security perspective, you should physically isolate segments
    > with different levels of security tolerance, whenever possible.

    I claim that one can do that with vlans, and it is a special case of
    "physically".

    > For segments with similar security tolerance, you might decide that
    > there are advantages in your scenario, although I'll still argue that
    > my points above are valid in most of the scenarios I've seen.

    I think we're looking at a sizing issue, the more networks you have,
    the more switches you need in this case.

    With vlans, more networks doesn't mean you need to buy more switches.

    I would like to encourage the use of vlans as a means of increasing
    security.

    I believe that since you can easily create many separate segments using
    vlan capable hardware you already own or are considering buying, this
    separation will encourage the practice of identifying and implementing
    more security between networks.

    You could create vlans for every class of machine, every department,
    every business function, whatever you wanted, and make them separate
    layer 2 networks.

    > In particular, if your infrastructure is small, it almost never pays
    > to go with a huge switch.... (just my $0.035 -- I never give just
    > $0.02! ;-)

    That is true. Buy the appropriate sized equipment for your network
    with the functions you require, and compare among vendors.

    Dale

    _______________________________________________
    firewall-wizards mailing list
    firewall-wizards@honor.icsalabs.com
    http://honor.icsalabs.com/mailman/listinfo/firewall-wizards


  • Next message: Devdas Bhagat: "Re: [fw-wiz] Evolution of Firewalls"

    Relevant Pages

    • Re: Multidimensionnal Hash table
      ... Perl for collecting data on a networks, sorted by switches, machines, ... Vlans ... ...
      (comp.lang.tcl)
    • Re: VLANs
      ... > I need to set up VLANS for a predominately Linux based environment. ... The above scenario would enable us share the switches between ... > the physical LANs while still maintaining separate broadcast domains. ... > separation of a highly critical data collection network. ...
      (comp.os.linux.networking)
    • [fw-wiz] Re: firewall-wizards digest, Vol 1 #1229 - 18 msgs
      ... >>onto their own switches does not scale. ... >>There are economies of scale in having bigger switches with more vlans, ... I, personally, am a very big fan of separate physical switches per ... Security is always a business decision, ...
      (Firewall-Wizards)
    • Re: VLANS and subnetting
      ... thats why i want to create Seperate VLANS, so that I could isolate the ... So if I were to use multiple VLANS, ... keep the individual PCs on separate IP subnets. ...
      (comp.dcom.lans.ethernet)
    • Re: number of ethernet adapters in a cluster
      ... >>By separating the protocols into different VLANS, ... And it also requires either a separate physical LAN for each of the ... three interfaces which means more hub/switch port ...
      (comp.os.vms)