Re: [fw-wiz] A fun smackdown...

From: Paul D. Robertson (paul_at_compuwar.net)
Date: 05/19/05

  • Next message: Chuck Swiger: "Re: [fw-wiz] A fun smackdown..."
    To: Chuck Swiger <chuck@codefab.com>
    Date: Thu, 19 May 2005 17:45:40 -0400 (EDT)
    
    

    On Thu, 19 May 2005, Chuck Swiger wrote:

    > Paul, why *don't* people run their firewalls with a single "deny all"
    > rule?
    >

    Actually, thinking about it, because it's cheaper to just not connect
    systems that don't need the risk, and you lose the risk of implementation
    errors in the firewall, configuration errors, and it then takes physical
    presence to bridge the gap, reducing the rate of attack (which is probably
    extremely low anyway.)

    Now I've got one for you; Why do some people run firewalls with a single
    "allow all" rule, and what can you do to make that less risky than the
    "deny all" example?

    Paul
    -----------------------------------------------------------------------------
    Paul D. Robertson "My statements in this message are personal opinions
    paul@compuwar.net which may have no basis whatsoever in fact."
    _______________________________________________
    firewall-wizards mailing list
    firewall-wizards@honor.icsalabs.com
    http://honor.icsalabs.com/mailman/listinfo/firewall-wizards


  • Next message: Chuck Swiger: "Re: [fw-wiz] A fun smackdown..."

    Relevant Pages

    • RE: [fw-wiz] Managed Firewall Service - Opinions
      ... On Mon, 21 Apr 2003, Melson, Paul wrote: ... Change is perceptibly risky. ... limit the risk in some scenerios that only someone with a deep view of the ... more than just the firewall ruleset (and costs a heck of a lot more than ...
      (Firewall-Wizards)
    • Re: [fw-wiz] Linux Firewall on CD
      ... >> the attacker wants an open relay for spamming. ... Presumably the firewall had some utility, ... The point is that you reduce a small ammount of additional risk by going ... Paul D. Robertson "My statements in this message are personal opinions ...
      (Firewall-Wizards)
    • RE: [fw-wiz] RPCs over HTTPS through the firewall
      ... >> it matter much if we add RPC to the sludge? ... > a similar risk profile, although encrypting traffic over 443 ... of the firewall admin's major bugbears. ...
      (Firewall-Wizards)
    • RE: RE: Front End/Back End communication
      ... communication between FE/BE via IPSEC then IF the front end server ... How likely is it that someone gets past your firewall? ... the FE and BE communicate in the clear. ... you against the real risk. ...
      (Focus-Microsoft)
    • [fw-wiz] New Security Risk Management Solution - Market Feedback Request
      ... We are soon going to be releasing a new security risk management ... solution and I would like to find out if anyone on the Firewall Wizards ... Pulls in firewall and router config files to draw an accurate network ...
      (Firewall-Wizards)