Re: [fw-wiz] X server in a Firewall



On Tue, 24 Jan 2006, Marcus J. Ranum wrote:
Indeed; if your firewall rulesets change so often that you find it
onerous to walk down the hall to the console, then your firewall
ruleset is changing too often, which probably means you are
already in a state of screwed.

Down the hall? Must be nice. I'm thinking "to another continent".

Frankly while I agree that firewall management should be done out of
band, there are certainly situations where physical access is not a
straightforward means of out of band access - and the environment is
legitimately dynamic.

cheers!
==========================================================================
"A cat spends her life conflicted between a deep, passionate and profound
desire for fish and an equally deep, passionate and profound desire to
avoid getting wet.  This is the defining metaphor of my life right now."
_______________________________________________
firewall-wizards mailing list
firewall-wizards@xxxxxxxxxxxxxxxxxx
http://honor.icsalabs.com/mailman/listinfo/firewall-wizards



Relevant Pages

  • Re: [fw-wiz] Firewall Primitives
    ... > firewall should simulate connections to the best of its ability. ... I'd included a query about using 'redirect', but I suspect that it got ... "A cat spends her life conflicted between a deep, passionate and profound ... desire for fish and an equally deep, passionate and profound desire to ...
    (Firewall-Wizards)
  • [fw-wiz] Ethics & hiring
    ... SecurePoint is not just a firewall company. ... "A cat spends her life conflicted between a deep, passionate and profound ... desire for fish and an equally deep, passionate and profound desire to ...
    (Firewall-Wizards)
  • Re: [fw-wiz] Firewall Primitives
    ... > about the basic elements that make up firewall rules and descriptors. ... > "A cat spends her life conflicted between a deep, passionate and profound ... > desire for fish and an equally deep, passionate and profound desire to ...
    (Firewall-Wizards)
  • Re: [fw-wiz] Thoughts on the new Cisco ASA 5500 firewalls
    ... >traffic flows for inspection, so at least this do not overload central CPU. ... All of the "Deep packet inspection" firewall/switches that I have ... "Deep Packet Inspection" is complete marketing malarkey. ... firewalls compared to a proxy firewall, and I did a short write-up ...
    (Firewall-Wizards)
  • Re: [fw-wiz] Firewalls Compared
    ... > replied "I tried to deploy your product with authentication on, ... This reminds me of a certain firewall vendor, ... "A cat spends her life conflicted between a deep, passionate and profound ... desire for fish and an equally deep, passionate and profound desire to ...
    (Firewall-Wizards)