Re: Proxies, opensource and the general market: what's wrong with us?

Tracy Reed <[email protected]> Mon, 25 Apr 2011 14:24:04 -0700
Newsgroups gmane.comp.security.firewalls.wizards
Message-ID <[email protected]>
On Sun, Apr 24, 2011 at 09:27:34PM +0400, ArkanoiD spake thusly:
> Now both are either extinct or forced to an ulgy low end (for
> opensource, 
>
> it usually means having no security-centric framework, 

What does this mean?

> no common API, 

How would a firewall API work and what would it do? What does "common"
mean in this context? Same API across multiple different firewall
vendors?

> no real code review 

Depends on what you mean by "real". I know tons of people look at the
Linux firewall code.

> -- just a bunch of "functionally fit" free things installed on a linux
> box with some simple web interface).

I don't know what "functionally fit" means either. 

As for web interfaces, most of the Linux firewalls I've used (especially
Shorewall, my favorite) have no web interface. I really don't want
someone managing my firewall who requires a web interface. I also like
to version control my firewall configs and back them up within my normal
backup infrastructure which most web interfaces cannot handle.

> I asked guys on LinkedIn (having to admit LinkedIn security community
> sucks big time, some sane people are still there :-) , if they still
> have some interest in opensource firewall solutions. The short answer
> was "NO". The long ones were:
>
> -- It is all about performance, we want as many Gbits per $ as
> possible, so ASIC is only way

The number of infrastructures that need firewalls which are transferring
< 100Mb/s are far greater in number than those pulling > 1Gb/s.  Do all
your LinkedIn pals work for Google, Facebook, etc? I have deployed lots
of firewalls and only a few ever handled more than a few hundred
megabits. The vast majority transfer at most on the order of single
megabits. Yet some of these single-digit-Mb/s firewalls protect large
numbers of credit card data and have serious security requirements.

> -- It is all about features and support, no free solution fits.

I can understand a company wanting support for their firewall. Support
costs someone's time and that quite fairly costs money. 

As for features, what features are the real sticking points here? Are we
just comparing bullet lists or do you really *need* certain features
which are lacking?

> Protocol support is not that good, no common management interface and

What protocols are we talking about here and what are we wanting to do
with them?

What is an example of a commercial product that has a common management
interface? What other product is it in common with?

> not really ready for enterprise which is not full of geeks at all,

I would think you would want to hire a geek to operate your firewall and
other security infrastructure if security was important to you.

> management overhead and TCO are going to jump up beyond any reasonable
> limit.

Why?

> OpenDLP is just a sad joke, running a bunch of regexps against your
> data is not the thing to be called DLP.

How do the commercial products do it?

> As I am still running the OpenFWTK project, I have to admit I get
> little to *NO* support form Opensource community.

I very rarely hear about openfwtk and I'm in the business. I know of
very few companies who have deployed or want to run proxies. Most just
stick with stateful packet filtering and maybe a squid/varnish proxy for
http and call it a day. In order to have community support you have to
have a community. There are 30 people in #shorewall on freenode.net and
for nearly 10 years now there has always been someone to help out
whenever I had an issue. The mailing list is quite active also. Tom
Eastep does a fantastic job of running the project working with the
community. openfwtk-devel at
http://sourceforge.net/mail/?group_id=192764 has 7 subscribers and 10
emails in the archive over years. And no IRC channel. It is barely
visible at all on the net. You don't get community support if you have
no community.

-- 
Tracy Reed

_______________________________________________
firewall-wizards mailing list
[email protected]
https://listserv.icsalabs.com/mailman/listinfo/firewall-wizards
signature.asc (application/pgp-signature, 197 B)
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.9 (GNU/Linux)

iEYEARECAAYFAk215nMACgkQBhSTPg0d/nSp2gCgjYIY2mrT/QRfXA15HOt9Yt0r
2gkAn13+OJ9zODruFpOEN44WUJkTVD3w
=ol1n
-----END PGP SIGNATURE-----