Re: [fw-wiz] Firewalls that generate new packets..
- From: "Marcus J. Ranum" <mjr@xxxxxxxxx>
- Date: Mon, 26 Nov 2007 14:01:15 -0500
Jim Seymour wrote:
What
you're telling me is just skip the firewall entirely, and put together
a comprehensive set of "firewall router" packet filtering rules.
That's not what I'm saying. I'm saying is that the action is all
at layer-7 these days. Use a router (or 2 tin cans and some string)
to apply broad, simple, controls at the network layer and make
sure you are directing traffic to locked down layer-7 services
on machines that you think can handle them.
Firewalls have always consisted (in my mind, anyhow..) of
"block and carry" - think of the basic stuff the firewall does
as blocking big chunks of traffic so that your layer-7 picture
is refined to the point where you can effectively reason
about it. In that model a proxy is just a "carry" tool for
layer-7 traffic - and you can then reason about the security
controls (if you're using more than just a plug-board
proxy, which is axiomatically the same as a router
permit port ACL) in the proxy.
With respect to the "stateful packet inspection" garbage;
it's computer security's equivalent of homeopathy or
accupuncture: people like it because it makes them
feel better. It's a placebo.
mjr.
_______________________________________________
firewall-wizards mailing list
firewall-wizards@xxxxxxxxxxxxxxxxxxxxx
https://listserv.icsalabs.com/mailman/listinfo/firewall-wizards
- Follow-Ups:
- Re: [fw-wiz] Firewalls that generate new packets..
- From: Darren Reed
- Re: [fw-wiz] Firewalls that generate new packets..
- From: Jim Seymour
- Re: [fw-wiz] Firewalls that generate new packets..
- References:
- Re: [fw-wiz] Firewalls that generate new packets..
- From: Paul Melson
- Re: [fw-wiz] Firewalls that generate new packets..
- From: Jim Seymour
- Re: [fw-wiz] Firewalls that generate new packets..
- Prev by Date: Re: [fw-wiz] Firewalls that generate new packets..
- Next by Date: Re: [fw-wiz] Firewalls that generate new packets..
- Previous by thread: Re: [fw-wiz] Firewalls that generate new packets..
- Next by thread: Re: [fw-wiz] Firewalls that generate new packets..
- Index(es):
Relevant Pages
|
|