Re: DISA eliminating firewalls

Tim Harris <[email protected]> Fri, 5 Jul 2013 09:21:27 -0700
Newsgroups gmane.comp.security.firewalls.wizards
Message-ID <[email protected]>
I think it's a mistake to assert that something will never happen.  I suspe=
ct that firewalls, per se, may disappear but the essential function will st=
ay.  The largest function that firewalls perform today is a coarse filterin=
g of traffic.  They eliminate the obvious bad traffic as well as traffic th=
at is misdirected.  I have no data on the percentage of traffic that never =
makes it through the firewall but suppose that it means the traffic behind =
the firewall is reduced by 20%.  That reduces my cost because I need less b=
andwidth and less robust equipment.  It also means I save on CPU cycles bec=
ause that traffic is checked once at the perimeter rather than forcing ever=
y device to inspect it.  This is why they still do ID checks at the door wh=
en entering a bar.  On the other hand, you can drive without a license if y=
ou are willing to take the chance of getting caught and paying the penalty.

I would argue that the next logical step in firewalls is a meta-firewall.  =
Suppose that I have a large, distributed network with multiple firewalls an=
d routers.  I argue that a good firewall software ought to be able to treat=
 that as a single administrative unit.  I define a set of rules similarly t=
o what I do now with my single firewall.  The meta-firewall should be able =
to analyze my routing and switch configuration, determine the rule set that=
 is appropriate to each individual device and push that out automatically. =
 That way I don't have to go to each single firewall, define a set of rules=
, and hope that they are consistent and correct.

The more points of management I have, the greater the opportunity for me to=
 screw it up.  By distributing the firewall function (which is what I suspe=
ct will really happen at DISA), as described in the article, there is a hug=
e administrative challenge for which I don't think there is a good solution=
 yet.

Respectfully,

Tim Harris


-----Original Message-----
From: [email protected] [mailto:firewall-wizar=
[email protected]] On Behalf Of Andr=E9 Lima
Sent: Thursday, July 04, 2013 11:27 AM
To: [email protected]
Subject: Re: [fw-wiz] DISA eliminating firewalls

Firewalls will never and should never disappear.
The reason is that multi-layer security systems are the best one can apply =
for any network. And by definition it means that one layer (e.g. =

firewall) will obviously not be enough, but nevertheless it is an essential=
 part or the security system. And the reason I believe it won't disappear i=
s that it gives us all some assurance. Just as the door in my house. If a g=
reat professional burgler wants to get something from our homes, the door w=
ill obviously  not stop him. But that doesn't mean I'm willing to give up m=
y door and just be in an open door home, because it does help in some situa=
tions (tipical strangers, or unwanted kids). I don't want to be inside and =
be worried that a drifting stranger might get inside and sleep in my bed wh=
ile I'm away just because there was nothing to stop him.
But if you're just implying that such system can be implemented, indeed tha=
t's possible. But that would be an end-to-end security system which is a ni=
ghtmare to maintain. A firewall is centralized and even though we all know =
it's not enough to mitigate all attacks, it does give me some basic assuran=
ces so I don't have to be (extremely?) paranoid inside my own network.

Best regards,
Andr=E9 Lima
http://www.andr3l1ma.net/