Re: [fw-wiz] Multiple firewalls from different manufactureres

From: Paul D. Robertson (paul_at_compuwar.net)
Date: 01/28/05

  • Next message: Paul D. Robertson: "RE: [fw-wiz] Multiple firewalls from different manufactureres"
    To: Shimon Silberschlag <shimons@bll.co.il>
    Date: Fri, 28 Jan 2005 09:30:10 -0500 (EST)
    
    

    On Thu, 27 Jan 2005, Shimon Silberschlag wrote:

    > Paul,
    >
    > I was more aiming to the issue of having the FW made by different
    > manufacturers. There is a lot to be gained from having a common platform
    > that the admins are familiar with, the chances for human errors are reduced,
    > to say the least.

    That was the basis of my "single layer of failure" comment, and why I
    wouldn't buy a firewall from my router vendor- I *want* different code.

    If your technical stall can't handle two firewall products, it's time to
    trade out the staff, not the products.

    > And yes, I too advocate the use of a screening router in front of the
    > external FW. The question is, do I *have* to get a different brand FW for
    > the internal one? And if the answer is yes, what's the reasoning?

    We'll still have failures in things like VPNs, IPv6 will probably have all
    the vendors doing all the old stupid stuff and some new stupid stuff, if
    you're using authentication, that tends to be tricky, etc.

    > Do you see "head-on" attacks on the fw (trying to get to the fw in spite of
    > a stealth rule defined) as a viable/sizeable threat today?

    It's never been just about the firewall, transport layer and state engine
    bugs have happened in the past, let's not even talk about the folks who
    think IPS on the firewall is a rocking good thing and the parsing
    issues and update of the month stuff that happens there.

    I like having one statefull thing outside, and one proxy inside- and I like
    a router between the inside users and the inside firewall too. Less
    chance for bad stuff to happen either from the inside or the outside.

    Paul
    -----------------------------------------------------------------------------
    Paul D. Robertson "My statements in this message are personal opinions
    paul@compuwar.net which may have no basis whatsoever in fact."
    _______________________________________________
    firewall-wizards mailing list
    firewall-wizards@honor.icsalabs.com
    http://honor.icsalabs.com/mailman/listinfo/firewall-wizards


  • Next message: Paul D. Robertson: "RE: [fw-wiz] Multiple firewalls from different manufactureres"

    Relevant Pages

    • Re: Please enable firewalls by default on Linux distributions
      ... > having a firewall does not help if the user is stupid enough. ... It helps a little if their stupid enough to leave it on. ... OS'es and routers come with security installed to prevent users from ... Kindof short-sighted. ...
      (comp.os.linux.security)
    • Re: (more) firewall advice please?
      ... and I don't encourage 3rd party software. ... Otherwise, if you aren't stupid, ... Norton Personal Firewall can prevent any and all ... pop-ups and ads by both preventing certain sites or all sites from using ...
      (comp.security.firewalls)
    • Re: three solutions for one Linux box
      ... Define "safe". ... although there is an external firewall allowing NAT access out (but ... What is your Linux distribution supposed to be doing? ... as a server for many applications (which is an incredibly stupid idea). ...
      (comp.security.firewalls)
    • Re: NTP firewall port not being opened up on FC3
      ... >> Because I don't want something I don't know about opening up my ... >> I always thought this was a stupid idea and I'm glad they changed it. ... application should never be able to open the firewall itself. ... Life is short, but wide. ...
      (linux.redhat)
    • Re: ics and firewall
      ... That falls under the "protect yourself by not being stupid" (i.e. remove ... security isn't just a firewall. ... Someone who has a firewall but does not use ... >>>it so that minimal damage can be done, or make it so that although you ...
      (comp.security.firewalls)