Re: [fw-wiz] Firewall rules order and performance
- From: Eric Gearhart <eric@xxxxxxxxxxxxx>
- Date: Tue, 28 Jul 2009 14:06:24 -0700
On Mon, Jul 27, 2009 at 1:21 AM, Jean-Denis Gorin<jdgorin@xxxxxxxxxxxx> wrote:
Who remember that firewalls (as application gateways) was designed to solve (or
to ease a lot) the patch management problem?
Now, we are back to patch management as the solution for all problems because
dumb people (managers, marketers, buyers, system admins, network admins,
developers, or whatever fit your situation) are unable (or unwilling) to
understand what is a firewall, and what is it due for...
Part of the problem with your argument is that in order for e,g, a web
server to be reached, port 80 (and maybe port 443) have to be allowed
through the firewall. That fact alone means that the webservers have
to be patched, because as long as the firewall is allowing legitimate
traffic through, it could also be allowing malicious traffic
through...
--
Eric
http://nixwizard.net
_______________________________________________
firewall-wizards mailing list
firewall-wizards@xxxxxxxxxxxxxxxxxxxxx
https://listserv.icsalabs.com/mailman/listinfo/firewall-wizards
- Follow-Ups:
- Re: [fw-wiz] Firewall rules order and performance
- From: K K
- Re: [fw-wiz] Firewall rules order and performance
- From: Behm, Jeff
- Re: [fw-wiz] Firewall rules order and performance
- References:
- [fw-wiz] Firewall rules order and performance
- From: Pierre Blanchet
- Re: [fw-wiz] Firewall rules order and performance
- From: lordchariot
- Re: [fw-wiz] Firewall rules order and performance
- From: Marcus J. Ranum
- Re: [fw-wiz] Firewall rules order and performance
- From: Jean-Denis Gorin
- [fw-wiz] Firewall rules order and performance
- Prev by Date: Re: [fw-wiz] Firewall rules order and performance
- Next by Date: Re: [fw-wiz] Firewall rules order and performance
- Previous by thread: Re: [fw-wiz] Firewall rules order and performance
- Next by thread: Re: [fw-wiz] Firewall rules order and performance
- Index(es):
Relevant Pages
|