Re: DISA eliminating firewalls
Tim Harris <[email protected]> Fri, 5 Jul 2013 09:21:27 -0700
| Newsgroups | gmane.comp.security.firewalls.wizards |
|---|---|
| Message-ID | <[email protected]> |
I think it's a mistake to assert that something will never happen. I suspe= ct that firewalls, per se, may disappear but the essential function will st= ay. The largest function that firewalls perform today is a coarse filterin= g of traffic. They eliminate the obvious bad traffic as well as traffic th= at is misdirected. I have no data on the percentage of traffic that never = makes it through the firewall but suppose that it means the traffic behind = the firewall is reduced by 20%. That reduces my cost because I need less b= andwidth and less robust equipment. It also means I save on CPU cycles bec= ause that traffic is checked once at the perimeter rather than forcing ever= y device to inspect it. This is why they still do ID checks at the door wh= en entering a bar. On the other hand, you can drive without a license if y= ou are willing to take the chance of getting caught and paying the penalty. I would argue that the next logical step in firewalls is a meta-firewall. = Suppose that I have a large, distributed network with multiple firewalls an= d routers. I argue that a good firewall software ought to be able to treat= that as a single administrative unit. I define a set of rules similarly t= o what I do now with my single firewall. The meta-firewall should be able = to analyze my routing and switch configuration, determine the rule set that= is appropriate to each individual device and push that out automatically. = That way I don't have to go to each single firewall, define a set of rules= , and hope that they are consistent and correct. The more points of management I have, the greater the opportunity for me to= screw it up. By distributing the firewall function (which is what I suspe= ct will really happen at DISA), as described in the article, there is a hug= e administrative challenge for which I don't think there is a good solution= yet. Respectfully, Tim Harris -----Original Message----- From: [email protected] [mailto:firewall-wizar= [email protected]] On Behalf Of Andr=E9 Lima Sent: Thursday, July 04, 2013 11:27 AM To: [email protected] Subject: Re: [fw-wiz] DISA eliminating firewalls Firewalls will never and should never disappear. The reason is that multi-layer security systems are the best one can apply = for any network. And by definition it means that one layer (e.g. = firewall) will obviously not be enough, but nevertheless it is an essential= part or the security system. And the reason I believe it won't disappear i= s that it gives us all some assurance. Just as the door in my house. If a g= reat professional burgler wants to get something from our homes, the door w= ill obviously not stop him. But that doesn't mean I'm willing to give up m= y door and just be in an open door home, because it does help in some situa= tions (tipical strangers, or unwanted kids). I don't want to be inside and = be worried that a drifting stranger might get inside and sleep in my bed wh= ile I'm away just because there was nothing to stop him. But if you're just implying that such system can be implemented, indeed tha= t's possible. But that would be an end-to-end security system which is a ni= ghtmare to maintain. A firewall is centralized and even though we all know = it's not enough to mitigate all attacks, it does give me some basic assuran= ces so I don't have to be (extremely?) paranoid inside my own network. Best regards, Andr=E9 Lima http://www.andr3l1ma.net/