RE: [fw-wiz] so much for "deny all"

From: Tina Bird (tbird_at_precision-guesswork.com)
Date: 06/10/05

  • Next message: Chuck Swiger: "Re: [fw-wiz] Host based vs network firewall in datacenter"
    To: <dave@corecom.com>
    Date: Fri, 10 Jun 2005 14:51:24 -0700
    
    

    > On 7 Jun 2005 at 9:41, Tina Bird wrote:
    >
    > > >From the TechTarget coverage of the Gartner Security Summit this
    > > >week:
    > >
    > > "Next generation firewalls that do deep-packet inspections from
    > > vendors like Juniper Networks, Check Point and Fortinet employ a
    > > heuristics engine and allow all network traffic and behavior, except
    > > those which policy says it must block. Most enterprises, however,
    > > refresh their firewall purchases on a three- to five-year cycle and
    > > that makes it challenging to synch new features."

    > From: Dave Piscitello [mailto:dave@corecom.com]
    >
    > This is very good publicity for firewall vendors not in the list who
    > provide a default "DENY ALL" in policy configuration. I'll enjoy
    > tormenting friends at these companies over this:-)

    I guess that's one way to look at it. I'd like to think that folks at those
    companies will be cringing, and refusing to pay for multi-martini lunches
    (if anyone in this politically correct time still indulges in multi-martini
    lunches). Although I wonder how many of the companies that ship with a "deny
    all" config will now be accused of being out of touch with the real world,
    or at least the real world as defined by Gartner.

    > But the 2nd statement is very odd, don't you think? Not only is it
    > remarkably difficult to parse, but it flies in the face of (my)
    > experience.
    >
    > Taking the source with a grain of salt, I find it hard to believe
    > that most enterprises change security vendors every five years.

    Well, the company at which I did my first firewall install replaced the
    whole shebang within a year of my leaving, claiming that my rock-solid
    Sidewinder infrastructure was too hard to manage, and putting in PIXen
    instead. But I agree that *most* places don't do that. We're generally
    content with the devil we know.

    > Perhaps 100% of my clients buck this trend. Upgrades, yes.
    > Forklifting firewalls? I have yet to see this except in circumstances
    > where the prior firewall failed pitifully in enforcing policy.

    I have seen several organizations replace firewall or VPN architectures, and
    almost never for a technical reason - almost always for political or
    financial ones.

    _______________________________________________
    firewall-wizards mailing list
    firewall-wizards@honor.icsalabs.com
    http://honor.icsalabs.com/mailman/listinfo/firewall-wizards


  • Next message: Chuck Swiger: "Re: [fw-wiz] Host based vs network firewall in datacenter"

    Relevant Pages

    • RE: [fw-wiz] CERT vulnerability note VU# 539363
      ... so vendors shoot for the former. ... > In my opinion if a stateful firewall claims it can filter at rate X ... > a stateless packet filter is going to be vulnerable to these sort ...
      (Firewall-Wizards)
    • Re: [fw-wiz] so much for "deny all"
      ... This is very good publicity for firewall vendors not in the list who ... where the prior firewall failed pitifully in enforcing policy. ... > vendors like Juniper Networks, Check Point and Fortinet employ a ...
      (Firewall-Wizards)
    • Re: How to choose an IDS/FW MSS provider
      ... > plenty of other competent vendors out there are doing R&D. ... > Firewall vendors are trying to catch up on the Layer 7 analysis. ... With the obvious success of IPS technologies at the perimeter, ...
      (Focus-IDS)
    • [fw-wiz] Firewall Sizing?
      ... How do you go about sizing a firewall? ... Anyway, as with most vendors there's a number of models and a number of specs that vary as you move up the range - throughput, max sessions, recommended users etc. ... What puts the most load on a modern firewall such as a Sidewinder, is it sheer throughput, is it keeping track of X sessions to/from Y clients and so on? ...
      (Firewall-Wizards)
    • Re: Tiny Vs Norton vs ZA
      ... >firewall if I had the urge. ... be-all of security on the Internet. ... >multiple vendors. ... >context of most home/personal users. ...
      (comp.security.firewalls)