Re: Firewall best practices
Martin Barry <[email protected]>
| Newsgroups | gmane.comp.security.firewalls.wizards |
|---|---|
| Message-ID | <[email protected]> |
$quoted_author = "Morty" ; > > If you have IDS, your perspective might change because crypto-enabled > ports cause you to lose insight. ...and every app that wants to work around a firewall just encrypts it's traffic and runs the server on port 443. It would be nice to not be "enumerating badness" and blacklisting IPs running services on port 443 that are against corporate policy but trying for "default deny and whitelist" would cause a DOS on support resources. cheers Marty