Re: DISA eliminating firewalls
Bennett Todd <[email protected]> Fri, 5 Jul 2013 11:07:34 -0400
| Newsgroups | gmane.comp.security.firewalls.wizards |
|---|---|
| Message-ID | <CAA9gXs96EMgK7pV=MDgatzbVUxKDSCOnjFkt4dsozeWKP4jLgg@mail.gmail.com> |
--===============1943812770== Content-Type: multipart/alternative; boundary=047d7b6da6acfab65f04e0c50dd9 --047d7b6da6acfab65f04e0c50dd9 Content-Type: text/plain; charset=ISO-8859-1 Thanks for sharing that provocative article. I find this peculiarly annoying. It seems to use the noun Firewall in the belief that there's a definition that everyone agrees on. Ever since the argument began between advocates of packet filters and those who favour application-level proxies, I've been using a definition, which I'm sure I borrowed from someone else: a system, deployed at a network traffic choke point, to help implement that portion of a security policy that can be expressed in terms of traffic flows. I'd like to hope that what the author is describing is an effort to shift security towards the edges of the network, where both the data and the diversity hang out. But if the need to attempt to enforce security policy on network traffic is still present, there's still going to be a need for a firewall; and if it morphs into a management tool for coordinating all the vast array of control tools on everything from phones to printers to network attached storage to routers, I'm not terribly optimistic. -Bennett <[email protected]> --047d7b6da6acfab65f04e0c50dd9 Content-Type: text/html; charset=ISO-8859-1 <p dir="ltr">Thanks for sharing that provocative article.</p> <p dir="ltr">I find this peculiarly annoying. It seems to use the noun<br> Firewall in the belief that there's a definition that everyone agrees<br> on.</p> <p dir="ltr">Ever since the argument began between advocates of packet filters and<br> those who favour application-level proxies, I've been using a<br> definition, which I'm sure I borrowed from someone else: a system,<br> deployed at a network traffic choke point, to help implement that<br> portion of a security policy that can be expressed in terms of traffic<br> flows.</p> <p dir="ltr">I'd like to hope that what the author is describing is an effort to<br> shift security towards the edges of the network, where both the data<br> and the diversity hang out.</p> <p dir="ltr">But if the need to attempt to enforce security policy on network<br> traffic is still present, there's still going to be a need for a<br> firewall; and if it morphs into a management tool for coordinating all<br> the vast array of control tools on everything from phones to printers<br> to network attached storage to routers, I'm not terribly optimistic.</p> <p dir="ltr">-Bennett<br> <<a href="mailto:[email protected]">[email protected]</a>></p> --047d7b6da6acfab65f04e0c50dd9-- --===============1943812770== Content-Type: text/plain; charset="us-ascii" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit Content-Disposition: inline _______________________________________________ firewall-wizards mailing list [email protected] https://listserv.icsalabs.com/mailman/listinfo/firewall-wizards --===============1943812770==--