Re: [fw-wiz] IPS vs. Firewalls



ArkanoiD wrote:
(I'd even say that anyone who seriously claim that IPS can replace firewall
is stupid moron with lack of understanding even security basics, and if
those people are allowed to make technical decisions your company has damn
big management problems)

I agree, but something must be added.
A pure IPS can't replace a firewall if it's doing just application protocol analisys/control. You still need policies. A IPS-firewall (stateful inspection + policy + layer7 inspection) can replace and sometimes do better than a firewall (stateful inspection + policy)


regards
Gabriele
begin:vcard
fn:Gabriele Buratti
n:Buratti;Gabriele
org:NETASQ Italia;Presales
adr:;;via Giovanni da Udine, 34;Milano;MI;20156;Italy
email;internet:gabriele.buratti@xxxxxxxxxx
tel;work:+39 02 38093754
tel;fax:+39 02 38093752
x-mozilla-html:FALSE
url:http://www.netasq.com
version:2.1
end:vcard



Relevant Pages

  • Re: Management vs. IT staff (was: Re: [fw-wiz] IPS vs. Firewalls)
    ... (I'd even say that anyone who seriously claim that IPS can replace firewall ... is stupid moron with lack of understanding even security basics, ... That's what i call "big management problems". ... A stupid moron is not a person ...
    (Firewall-Wizards)
  • RE: [fw-wiz] Arch questions
    ... > basics are as follows ... bewteen the inet> rtr and the firewall, with public adressing on the web. ... that same obscurity can be a problem ... be 'more secure' because of your understanding of the environment - the ...
    (Firewall-Wizards)
  • Re: Is it possible for someone to access my HD even though I am running a firewall?
    ... > Is there any possibility that my security has been compromised? ... A "personal" firewall is only as strong as the person that set it up. ... protection. ... understanding what they are doing. ...
    (comp.security.firewalls)
  • Re: firewall on FreeBSD
    ... >> understanding of how information is moved across the internet. ... >> IPFW is for the advanced firewall users who have expert ... >> with Ipfilter and when you find out that you have needs which are ... >> not met by Ipfilter then move over to IPFW. ...
    (freebsd-questions)
  • Re: 2 software firewalls simultaneously?
    ... of ipfw as another layer of firewall requires some understanding of ... firewall is already providing. ... understanding of how to write rules. ...
    (comp.sys.mac.apps)