Re: Frontiernet insists on being my firewall...
From: Moe Trin (ibuprofin_at_painkiller.example.tld)
Date: 08/31/04
- Next message: Moe Trin: "Re: Frontiernet insists on being my firewall..."
- Previous message: destined: "Re: Jetico Personal Firewall"
- In reply to: William Wallace: "Re: Frontiernet insists on being my firewall..."
- Next in thread: ozzy: "Re: Frontiernet insists on being my firewall..."
- Messages sorted by: [ date ] [ thread ] [ subject ] [ author ] [ attachment ]
Date: Mon, 30 Aug 2004 21:55:09 -0500
In article <7e4865b7.0408292217.745b45f6@posting.google.com>,
William Wallace wrote:
>> Even the friendly folk over at NSA (http://www.nsa.gov/snac/index.html)
>> are recommending that.
That page 404's now. Sorry
>They are probably recommending that ISPs block their customer's outbound
>pings, too
Actually the page was more generic than that, and was suggesting how
to set up _any_ perimeter security. I suspect it's based on work by
Cisco, but I also see references to what might be called "classic"
firewall books, such as D. Chapman and E. Zwicky. Building Internet
Firewalls (O'Reilly) and S. Bellovin and W. Cheswick. Network Firewalls.
Looking at the first book, their recommendations (Chapter 22) are even
tighter than the NSA recommendations.
_MOST_ firewall recommendations are such that you can do things to
outsiders (such as ping), but they can't do those things to you.
Where this breaks down is that your outbound (exanoke) ping is blocked
by the next hop's inbound filter rules. As mentioned, the internet is
not the wide open friendly place it once was.
>> >Frontiernet installing firewalls to block ports adds latency,
>>
>> Shouldn't add that much.
>
>It depends on what type of firewall they are using. 5mS here, 10mS
>there, and pretty sure you cannot game or hold a reasonable conversation.
Yeah, but if the link uses geostationary satellites you're looking at
a quarter second in propagation delay right there. Still, that delay
hasn't killed "overseas" telephone service. I've even used links with
round trip times over two-thirds of a second for both audio AND video.
That's getting pretty ropey, but it served the function needed.
Old guy
- Next message: Moe Trin: "Re: Frontiernet insists on being my firewall..."
- Previous message: destined: "Re: Jetico Personal Firewall"
- In reply to: William Wallace: "Re: Frontiernet insists on being my firewall..."
- Next in thread: ozzy: "Re: Frontiernet insists on being my firewall..."
- Messages sorted by: [ date ] [ thread ] [ subject ] [ author ] [ attachment ]
Relevant Pages
|