Re: DISA eliminating firewalls

Bennett Todd <[email protected]> Fri, 5 Jul 2013 11:07:34 -0400
Newsgroups gmane.comp.security.firewalls.wizards
Message-ID <CAA9gXs96EMgK7pV=MDgatzbVUxKDSCOnjFkt4dsozeWKP4jLgg@mail.gmail.com>
--===============1943812770==
Content-Type: multipart/alternative; boundary=047d7b6da6acfab65f04e0c50dd9

--047d7b6da6acfab65f04e0c50dd9
Content-Type: text/plain; charset=ISO-8859-1

Thanks for sharing that provocative article.

I find this peculiarly annoying. It seems to use the noun
Firewall in the belief that there's a definition that everyone agrees
on.

Ever since the argument began between advocates of packet filters and
those who favour application-level proxies, I've been using a
definition, which I'm sure I borrowed from someone else: a system,
deployed at a network traffic choke point, to help implement that
portion of a security policy that can be expressed in terms of traffic
flows.

I'd like to hope that what the author is describing is an effort to
shift security towards the edges of the network, where both the data
and the diversity hang out.

But if the need to attempt to enforce security policy on network
traffic is still present, there's still going to be a need for a
firewall; and if it morphs into a management tool for coordinating all
the vast array of control tools on everything from phones to printers
to network attached storage to routers, I'm not terribly optimistic.

-Bennett
<[email protected]>

--047d7b6da6acfab65f04e0c50dd9
Content-Type: text/html; charset=ISO-8859-1

<p dir="ltr">Thanks for sharing that provocative article.</p>
<p dir="ltr">I find this peculiarly annoying. It seems to use the noun<br>
Firewall in the belief that there&#39;s a definition that everyone agrees<br>
on.</p>
<p dir="ltr">Ever since the argument began between advocates of packet filters and<br>
those who favour application-level proxies, I&#39;ve been using a<br>
definition, which I&#39;m sure I borrowed from someone else: a system,<br>
deployed at a network traffic choke point, to help implement that<br>
portion of a security policy that can be expressed in terms of traffic<br>
flows.</p>
<p dir="ltr">I&#39;d like to hope that what the author is describing is an effort to<br>
shift security towards the edges of the network, where both the data<br>
and the diversity hang out.</p>
<p dir="ltr">But if the need to attempt to enforce security policy on network<br>
traffic is still present, there&#39;s still going to be a need for a<br>
firewall; and if it morphs into a management tool for coordinating all<br>
the vast array of control tools on everything from phones to printers<br>
to network attached storage to routers, I&#39;m not terribly optimistic.</p>
<p dir="ltr">-Bennett<br>
&lt;<a href="mailto:[email protected]">[email protected]</a>&gt;</p>

--047d7b6da6acfab65f04e0c50dd9--

--===============1943812770==
Content-Type: text/plain; charset="us-ascii"
MIME-Version: 1.0
Content-Transfer-Encoding: 7bit
Content-Disposition: inline

_______________________________________________
firewall-wizards mailing list
[email protected]
https://listserv.icsalabs.com/mailman/listinfo/firewall-wizards

--===============1943812770==--