Re: ISA Server or Firewall Appliance?

From: Abe Getchell (mailing.list.spooler_at_gmail.com)
Date: 11/16/05

  • Next message: Thor (Hammer of God): "Re: ISA Server or Firewall Appliance?"
    Date: Wed, 16 Nov 2005 13:22:26 -0500
    To: "Susan Bradley, CPA aka Ebitz - SBS Rocks [MVP]" <sbradcpa@pacbell.net>
    
    

    Hi Susan,

    You bring up a good point concerning misconfiguration (of course it's
    possible to misconfigure an appliance firewall), but with an appliance
    solution there's simply less to misconfigure in the first place; either
    the component simply doesn't exist or the administrator isn't given
    (direct) access to screw it up.

    However, that being said, having people who understand firewalls and can
    manage them appropriately isn't at question here, that's an HR issue.
    What is at question here is which piece of technology, that the original
    posted described, is better suited to be a perimeter firewall. We're
    talking pure technology here, as is usually implied when asking a "which
    is better" question on a technology mailing list. We just assume that
    regardless of the solution it will be managed competently (though we
    shouldn't... we really, really, shouldn't).

    Simply going through the basic build/configuration/management process
    and comparing the steps/processes involved will give you a clear picture
    as to why appliance solutions (such as Check Point's SPLAT or Cisco's
    PIX) are much less complex than a "general purpose" solution (such as
    Windows/ISA or Linux/IPTables). I'll spare you (and everyone else) the
    lengthy e-mail (unless you really, really, want it) and let you go
    through that exercise on your own, if you choose.

    Abe

    -- 
    Abe Getchell
    abegetchell@gmail.com
    http://abegetchell.com/
    Susan Bradley, CPA aka Ebitz - SBS Rocks [MVP] wrote:
    > I've seen/read the CISCO security guides on NSA... I've seen 
    > misconfigured appliance firewalls.  There's a lot of complexity out 
    > there even in these dedicated devices.
    > 
    > I'm not convinced 'the vast majority of that complexity doesn't exist' 
    > is a valid statement anymore  in what we have going through our 
    > firewalls these days and what we have installed.
    > 
    > I'm a SBSer so throw me out the best practices window anyway as I break 
    > all of 'em ... but take a box [a], stick a secure.inf template on it or 
    > run the Secure Configuration Wizard, I'm just not convinced that unless 
    > you have folks that understand that firewall you can make such blanket 
    > statements these days.
    > 
    > 
    > 
    > Cisco Router Security Recommendation Guides // National Security Agency //:
    > http://nsa2.www.conxion.com/cisco/
    > 
    > [a] and when I say ..take a box... that means Windows 2003 only, 2000 
    > even with .inf's applied just isn't the same beast.
    ---------------------------------------------------------------------------
    ---------------------------------------------------------------------------
    

  • Next message: Thor (Hammer of God): "Re: ISA Server or Firewall Appliance?"

    Relevant Pages

    • Re: Firewall Comparisons
      ... On Mon, 2003-07-07 at 09:30, Bryan S. Sampsel wrote: ... based firewall comes on an already hardened OS. ... You can misconfigure a software or firmware based firewall, ... Evaluating SSL VPNs' Consider NEOTERIS, chosen as leader by top analysts! ...
      (Security-Basics)
    • Re: Zotob worm patch?
      ... If the firewall fails you don't have any internet ... If you misconfigure it, most times you're still ... not to apply critical patches. ...
      (microsoft.public.windowsxp.general)
    • RE: Insecurity of a not well configured firewall
      ... > firewall, is ... Yes, and in fact, I would count on it, if you misconfigure your firewall. ... Redhat Linux 5.0 machine without patches put on the internet is something ...
      (RedHat)
    • Re: Firewall yes, but where?
      ... > function of the firewall, ... I will also apologize for my English; ... Appliance firewall versus personal firewall is a difficult one to answer ...
      (comp.security.firewalls)