RE: [fw-wiz] Multiple firewalls from different manufactureres

From: Hurst, Dave (dhurst_at_lisletech.com)
Date: 01/28/05

  • Next message: damnliberals_at_gmail.com: "Re: [fw-wiz] Multiple firewalls from different manufactureres"
    To: "'firewall-wizards@honor.icsalabs.com'" <firewall-wizards@honor.icsalabs.com>
    Date: Fri, 28 Jan 2005 13:40:28 -0600
    
    

    Kevin Kadow wrote:
    > > I still try to at least get a screening router up front that does
    have a
    > > different packet filtering implementation (so I don't generally use
    green
    > > firewalls.) To me, it's a matter of not designing easy to fail
    > > infrastructure.
    >
    > At a minimum, a screening router in front of any firewall makes a lot
    of sense,
    > and recently I've started to deploy screening routers on the inside to
    filter
    > default route outbound traffic.
    [...]
    > > With two devices, you have the chance to catch configuration
    failures, not
    > > just implementation failures. If possible, it's nice to have two
    > > different groups handling each piece in coordination, so that you
    have to
    > > have two people co-opted to start punching holes, especially
    > > admin-installed backdoors.
    [...]
    > Deploying multiple different types of security device in series adds
    cost,
    > complexity, and failure modes. Managing the infrastructure requires
    > more staff with more diverse skills, and the coordination required to
    > "punch holes" will increase the effort and delay when changes are
    > legitimately required.
    [...]
    > > Do you see such setups implemented? Or does most setups include a
    > > single FW with multiple DMZs, connected directly to the internal
    network?
    >
    > I see a lot of setups where multiple firewalls from different
    manufacturers
    > are deployed, in parallel.

    I certainly agree that multiple devices, be they firewalls, routers, or
    whatever, layered to provide defense in depth provides a more secure
    network. Do people have any sense for how often organizations actually
    follow this best practice? Or is it considered too complex and too
    difficult to manage effectively, i.e. one firewall is "good enough" so
    it's just left at that?

    --DaveH "Be Excellent to each other!"
    _______________________________________________
    firewall-wizards mailing list
    firewall-wizards@honor.icsalabs.com
    http://honor.icsalabs.com/mailman/listinfo/firewall-wizards


  • Next message: damnliberals_at_gmail.com: "Re: [fw-wiz] Multiple firewalls from different manufactureres"

    Relevant Pages

    • Re: AntiSpyware alone sufficient
      ... I've not had as much experience with firewalls as av, ... Once malware is running, it can defend itself - the essence of combat ... multiple av or firewalls cause problems. ... against code defects, risk management of poor design, choice of decent ...
      (microsoft.public.windowsxp.security_admin)
    • Re: Can XP PS2 firewall coexist with Other firewals?
      ... Frank wrote: ... TIA ... >>I have run multiple firewalls for several years, ... I've heard that multiple FW may ...
      (comp.security.firewalls)
    • Re: Userenv error EventID: 1000
      ... The DC's have multiple NIC's, ... ports, but really doesn't specifically say which ports are required or not ... Active Directory Replication over Firewalls - Microsoft Service Providers: ...
      (microsoft.public.win2000.group_policy)
    • Re: Userenv error EventID: 1000
      ... The DC's have multiple NIC's, ... ports, but really doesn't specifically say which ports are required or not ... Active Directory Replication over Firewalls - Microsoft Service Providers: ...
      (microsoft.public.win2000.dns)
    • Re: Userenv error EventID: 1000
      ... The DC's have multiple NIC's, ... ports, but really doesn't specifically say which ports are required or not ... Active Directory Replication over Firewalls - Microsoft Service Providers: ...
      (microsoft.public.win2000.general)