Re: [fw-wiz] FW appliance comparison - Seeking input for the forum
- From: Anton Chuvakin <anton@xxxxxxxxxxxx>
- Date: Wed, 25 Jan 2006 18:03:41 -0500
> Though i think people who buy Checkpoint stuff are somehow non-representative
> (i think if one tried that with, say, Cyberguard, we'd see completely
> different picture) the results are still scary. Damn scary. That means 80%
> firewalls could be thrown off with no further harm to security.
I've been meaning to stay away from this fun, but [by far] too bigoted
discussion, but this spiked my curiosity. What't wrong with Checkpoint
[in this context]? I have a sneaking suspicion that its the pretty
GUI. Am I correct?
However, I suspect that a "pretty GUI" is a reasons the results for
Cybergard (or, iptables, for that matter) will be way more horrendous.
A well-designed and intuitive rule UI will likely work to reduce the
errors made by the admins thus, indirectly, incresing security and the
value of a firewall.
On a related note, I was shocked when I've heard that some org was
choosing an anti-virus (from all things!) based on its management UI
intuitiveness, but it does make sense on some level: bad UI -> admins
hate the product -> its not used / not configured right -> security
suffers.
Thus, "pretty UI" = "higher security" :-)
Fight on! :-)
Best,
--
Anton Chuvakin, Ph.D., GCIA, GCIH, GCFA http://www.chuvakin.org
http://www.securitywarrior.com
_______________________________________________
firewall-wizards mailing list
firewall-wizards@xxxxxxxxxxxxxxxxxx
http://honor.icsalabs.com/mailman/listinfo/firewall-wizards
- References:
- Re: [fw-wiz] FW appliance comparison - Seeking input for the forum
- From: sai
- Re: [fw-wiz] FW appliance comparison - Seeking input for the forum
- From: Paul D. Robertson
- Re: [fw-wiz] FW appliance comparison - Seeking input for the forum
- From: Avishai Wool
- Re: [fw-wiz] FW appliance comparison - Seeking input for the forum
- From: ArkanoiD
- Re: [fw-wiz] FW appliance comparison - Seeking input for the forum
- Prev by Date: RE: [fw-wiz] FW appliance comparison - Seeking input for the forum
- Next by Date: Re: [fw-wiz] RE: IDS (was: FW appliance comparison)
- Previous by thread: RE: [fw-wiz] FW appliance comparison - Seeking input for the forum
- Next by thread: Re: [fw-wiz] FW appliance comparison - Seeking input for the forum
- Index(es):