Re: [fw-wiz] Firewalls that generate new packets..
- From: "Paul Melson" <pmelson@xxxxxxxxx>
- Date: Mon, 26 Nov 2007 09:44:57 -0500
Isn't that kind of amazing? People look at these "stateful firewalls" asif they're somehow
doing something IMPORTANT but they're basically a router with"established" and a kind of
"synthetic established" for UDP. People, that's barely a security deviceat all - 99% of what
you're getting is the "firewall" sticker on the front.
You're overlooking the real value of state tables, I think. The real
advantage isn't technical, it's cognitive. If I don't have to think about,
decide on, classify, and manage all ends of the traffic crossing my border,
my life is a whole lot easier. A stateful firewall lets you think about
your policy in terms of published services; "I let the whole Internet
connect to this web server and that mail server, but nothing else. And then
whatever our people inside want to do."
Call it cynical. Call it misguided. Call it naive. Call it stupid. But
it saves time and energy which translates to money. And it seems to be
where the equilibrium for the firewall security vs. admin overhead equation
is, or at least has been in recent history.
PaulM
_______________________________________________
firewall-wizards mailing list
firewall-wizards@xxxxxxxxxxxxxxxxxxxxx
https://listserv.icsalabs.com/mailman/listinfo/firewall-wizards
- Follow-Ups:
- Re: [fw-wiz] Firewalls that generate new packets..
- From: Jim Seymour
- Re: [fw-wiz] Firewalls that generate new packets..
- References:
- Re: [fw-wiz] Firewalls that generate new packets..
- From: Bill McGee (bam)
- Re: [fw-wiz] Firewalls that generate new packets..
- From: Paul D. Robertson
- Re: [fw-wiz] Firewalls that generate new packets..
- From: Marcus J. Ranum
- Re: [fw-wiz] Firewalls that generate new packets..
- Prev by Date: Re: [fw-wiz] Firewalls that generate new packets..
- Next by Date: Re: [fw-wiz] Firewalls that generate new packets..
- Previous by thread: Re: [fw-wiz] Firewalls that generate new packets..
- Next by thread: Re: [fw-wiz] Firewalls that generate new packets..
- Index(es):
Relevant Pages
|