Re: DISA eliminating firewalls

"Young,Greg" <[email protected]> Sat, 6 Jul 2013 18:33:26 +0000
Newsgroups gmane.comp.security.firewalls.wizards
Message-ID <[email protected]>
--===============0826379384==
Content-Language: en-US
Content-Type: multipart/alternative;
	boundary="_000_25D308BE2CEA4C45BECDB9C067C5DBDBgartnercom_"

--_000_25D308BE2CEA4C45BECDB9C067C5DBDBgartnercom_
Content-Type: text/plain; charset="windows-1256"
Content-Transfer-Encoding: quoted-printable

BYOD doesn't mean give up on the network edge and firewalls.  And a more co=
mplex Internet edge doesn't mean your data center doesn't need protecting f=
rom the outside and the WAN: just the opposite.  This is why the increase i=
n defence in depth.  As long as end points are not all  vulnerability free =
and all managed we can't exclusively rely on host security.  And firewalls =
aren't the silver bullet, but they can sure narrow the aperture for attacks=
.

This is a similar discussion to the ones a few years ago around the Jericho=
 Forum.  Anyone up for hanging their data server off the inet?  Have an upd=
ated CV if you do.

I think that article speaks more to the frustrations around data security r=
eally.  Data security and network security aren't exclusive though.



On 2013-07-06, at 12:11 PM, "Crispin Cowan" <[email protected]<mailt=
o:[email protected]>> wrote:

=93What will happen when firewalls go away?=94 is a very good question, i d=
on=92t have that answer. I simply assert that firewalls will go away, becau=
se they will become irrelevant. They are already barely relevant because of=
 mobile devices. The threatscape is ignoring your firewall and walking stra=
ight through the front door attached to each individual worker in the form =
of a smart phone or a tablet. Not only do the users use them any way they w=
ant while away from the office, most of these devices are dual-homed to you=
r network and a cellular network plumped right to the internet.

It is neither my choice nor my wish that firewalls will go away, merely an =
inevitable consequence of pervasive mobile computing in the enterprise.

Sent from Windows Mail

From: Tim Harris
Sent: =FDSaturday=FD, =FDJuly=FD =FD6=FD, =FD2013 =FD8=FD:=FD11=FD =FDAM
To: Firewall Wizards Security Mailing List

I don=92t disagree with your comment about the crunchy outside/gooey middle=
 but If firewalls are to go away, what will happen to the function they per=
form?  Are we going to discard the entire function of coarse filtering?  It=
 has been amply demonstrated that the individual device is not currently ca=
pable of adequately defending itself.

Going back to my other comment about many points of administration, is ther=
e a software package or system that can/will reduce it down to a manageable=
 problem?  Is there a =93meta-admin=94 system out there or under developmen=
t?

From: [email protected]<mailto:firewall-wizard=
[email protected]> [mailto:firewall-wizards-bounces@listserv.=
icsalabs.com] On Behalf Of Crispin Cowan
Sent: Friday, July 05, 2013 12:04 PM
To: Firewall Wizards Security Mailing List
Subject: Re: [fw-wiz] DISA eliminating firewalls

Firewalls are virtually guaranteed to disappear. The writing was on the wal=
l the first time =93crunchy outside, gooey middle=94 was uttered. Smart pho=
nes and tablets dig the hole deeper, and BYOD is the nail in the coffin.

You cannot protect your networks in a world full of smart phones and tablet=
s, owned by consumers, which must be allowed to connect to the network. The=
 only thing you can do at that point is to stop trusting the network, and i=
nstead trust individual nodes, and use encrypted channels (IPsec, SSL, what=
ever) between nodes that trust each other.

When this will happen is far less clear, and it may be that DISA is a bit p=
remature here. But this is coming, get used to it.

Sent from Windows Mail


_______________________________________________
firewall-wizards mailing list
[email protected]<mailto:[email protected]=
alabs.com>
https://listserv.icsalabs.com/mailman/listinfo/firewall-wizards

________________________________

This e-mail message, including any attachments, is for the sole use of the =
person to whom it has been sent, and may contain information that is confid=
ential or legally protected. If you are not the intended recipient or have =
received this message in error, you are not authorized to copy, distribute,=
 or otherwise use this message or its attachments. Please notify the sender=
 immediately by return e-mail and permanently delete this message and any a=
ttachments. Gartner makes no warranty that this e-mail is error or virus fr=
ee.

--_000_25D308BE2CEA4C45BECDB9C067C5DBDBgartnercom_
Content-Type: text/html; charset="windows-1256"
Content-Transfer-Encoding: quoted-printable

<html>
<head>
<meta http-equiv=3D"Content-Type" content=3D"text/html; charset=3Dwindows-1=
256">
</head>
<body dir=3D"auto">
<div>BYOD doesn't mean give up on the network edge and firewalls. &nbsp;And=
 a more complex Internet edge doesn't mean your data center doesn't need pr=
otecting from the outside and the WAN: just the opposite. &nbsp;This is why=
 the increase in defence in depth. &nbsp;As long
 as end points are not all &nbsp;vulnerability free and all managed we can'=
t exclusively rely on host security. &nbsp;And firewalls aren't the silver =
bullet, but they can sure narrow the aperture for attacks.</div>
<div><br>
</div>
<div>This is a similar discussion to the ones a few years ago around the Je=
richo Forum. &nbsp;Anyone up for hanging their data server off the inet? &n=
bsp;Have an updated CV if you do.</div>
<div><br>
</div>
<div>I think that article speaks more to the frustrations around data secur=
ity really. &nbsp;Data security and network security aren't exclusive thoug=
h.<br>
<br>
<div><br>
</div>
</div>
<div><br>
On 2013-07-06, at 12:11 PM, &quot;Crispin Cowan&quot; &lt;<a href=3D"mailto=
:[email protected]">[email protected]</a>&gt; wrote:<br>
<br>
</div>
<blockquote type=3D"cite">
<div><style>
<!--
p.MsoListParagraph, li.MsoListParagraph, div.MsoListParagraph
	{margin-top:0in;
	margin-right:0in;
	margin-bottom:0in;
	margin-left:.5in;
	margin-bottom:.0001pt}
p.MsoListParagraphCxSpFirst, li.MsoListParagraphCxSpFirst, div.MsoListParag=
raphCxSpFirst, p.MsoListParagraphCxSpMiddle, li.MsoListParagraphCxSpMiddle,=
 div.MsoListParagraphCxSpMiddle, p.MsoListParagraphCxSpLast, li.MsoListPara=
graphCxSpLast, div.MsoListParagraphCxSpLast
	{margin-top:0in;
	margin-right:0in;
	margin-bottom:0in;
	margin-left:.5in;
	margin-bottom:.0001pt;
	line-height:115%}
-->
</style><style>
<!--
p.MsoNormal, li.MsoNormal, div.MsoNormal
	{margin:0in;
	margin-bottom:.0001pt;
	font-size:12.0pt;
	font-family:"Times New Roman","serif"}
a:link, span.MsoHyperlink
	{color:blue;
	text-decoration:underline}
span.MsoHyperlinkFollowed
	{color:purple;
	text-decoration:underline}
p.MsoListParagraph, li.MsoListParagraph, div.MsoListParagraph
	{margin-top:0in;
	margin-right:0in;
	margin-bottom:0in;
	margin-left:.5in;
	margin-bottom:.0001pt;
	font-size:12.0pt;
	font-family:"Times New Roman","serif"}
p.msolistparagraphcxspfirst, li.msolistparagraphcxspfirst, div.msolistparag=
raphcxspfirst
	{margin-top:0in;
	margin-right:0in;
	margin-bottom:0in;
	margin-left:.5in;
	margin-bottom:.0001pt;
	line-height:115%;
	font-size:12.0pt;
	font-family:"Times New Roman","serif"}
p.msolistparagraphcxspmiddle, li.msolistparagraphcxspmiddle, div.msolistpar=
agraphcxspmiddle
	{margin-top:0in;
	margin-right:0in;
	margin-bottom:0in;
	margin-left:.5in;
	margin-bottom:.0001pt;
	line-height:115%;
	font-size:12.0pt;
	font-family:"Times New Roman","serif"}
p.msolistparagraphcxsplast, li.msolistparagraphcxsplast, div.msolistparagra=
phcxsplast
	{margin-top:0in;
	margin-right:0in;
	margin-bottom:0in;
	margin-left:.5in;
	margin-bottom:.0001pt;
	line-height:115%;
	font-size:12.0pt;
	font-family:"Times New Roman","serif"}
p.emailquote, li.emailquote, div.emailquote
	{margin-right:0in;
	margin-left:1.0pt;
	border:none;
	padding:0in;
	font-size:12.0pt;
	font-family:"Times New Roman","serif"}
span.EmailStyle22
	{font-family:"Calibri","sans-serif";
	color:#1F497D}
.MsoChpDefault
	{font-size:10.0pt}
-->
</style>
<div dir=3D"ltr" style=3D"font-family:Calibri,'Segoe UI',Meiryo,'Microsoft =
YaHei UI','Microsoft JhengHei UI','Malgun Gothic','Khmer UI','Nirmala UI',T=
unga,'Lao UI',Ebrima,sans-serif; font-size:12pt">
<div>=93What will happen when firewalls go away?=94 is a very good question=
, i don=92t have that answer. I simply assert that firewalls will go away, =
because they will become irrelevant. They are already barely relevant becau=
se of mobile devices. The threatscape
 is ignoring your firewall and walking straight through the front door atta=
ched to each individual worker in the form of a smart phone or a tablet. No=
t only do the users use them any way they want while away from the office, =
most of these devices are dual-homed
 to your network and a cellular network plumped right to the internet.</div=
>
<div><br>
</div>
<div>It is neither my choice nor my wish that firewalls will go away, merel=
y an inevitable consequence of pervasive mobile computing in the enterprise=
.<br>
</div>
<div>
<div><br>
</div>
<div>Sent from Windows Mail</div>
<div><br>
</div>
</div>
<div style=3D"padding-top:5px; border-top-color:rgb(229,229,229); border-to=
p-width:1px; border-top-style:solid">
<div><font face=3D"Calibri, 'Segoe UI', Meiryo, 'Microsoft YaHei UI', 'Micr=
osoft JhengHei UI', 'Malgun Gothic', 'Khmer UI', 'Nirmala UI', Tunga, 'Lao =
UI', Ebrima, sans-serif" style=3D"line-height:15pt; letter-spacing:0.02em; =
font-family:Calibri,&quot;Segoe UI&quot;,Meiryo,&quot;Microsoft YaHei UI&qu=
ot;,&quot;Microsoft JhengHei UI&quot;,&quot;Malgun Gothic&quot;,&quot;Khmer=
 UI&quot;,&quot;Nirmala UI&quot;,Tunga,&quot;Lao UI&quot;,Ebrima,sans-serif=
; font-size:11pt"><b>From:</b>&nbsp;Tim
 Harris<br>
<b>Sent:</b>&nbsp;=FDSaturday=FD, =FDJuly=FD =FD6=FD, =FD2013 =FD8=FD:=FD11=
=FD =FDAM<br>
<b>To:</b>&nbsp;Firewall Wizards Security Mailing List</font></div>
</div>
<div><br>
</div>
<div class=3D"WordSection1">
<p class=3D"MsoNormal"><span style=3D"color:rgb(31,73,125); font-family:&qu=
ot;Calibri&quot;,&quot;sans-serif&quot;; font-size:11pt">I don=92t disagree=
 with your comment about the crunchy outside/gooey middle but If firewalls =
are to go away, what will happen to the function they perform?&nbsp;
 Are we going to discard the entire function of coarse filtering?&nbsp; It =
has been amply demonstrated that the individual device is not currently cap=
able of adequately defending itself.</span></p>
<p class=3D"MsoNormal"><span style=3D"color:rgb(31,73,125); font-family:&qu=
ot;Calibri&quot;,&quot;sans-serif&quot;; font-size:11pt">&nbsp;</span></p>
<p class=3D"MsoNormal"><span style=3D"color:rgb(31,73,125); font-family:&qu=
ot;Calibri&quot;,&quot;sans-serif&quot;; font-size:11pt">Going back to my o=
ther comment about many points of administration, is there a software packa=
ge or system that can/will reduce it down to a manageable
 problem? &nbsp;Is there a =93meta-admin=94 system out there or under devel=
opment?</span></p>
<p class=3D"MsoNormal"><span style=3D"color:rgb(31,73,125); font-family:&qu=
ot;Calibri&quot;,&quot;sans-serif&quot;; font-size:11pt">&nbsp;</span></p>
<div>
<div style=3D"border-width:1pt medium medium; border-style:solid none none;=
 border-color:rgb(225,225,225) black black; padding:3pt 0in 0in">
<p class=3D"MsoNormal"><b><span style=3D"font-family:&quot;Calibri&quot;,&q=
uot;sans-serif&quot;; font-size:11pt">From:</span></b><span style=3D"font-f=
amily:&quot;Calibri&quot;,&quot;sans-serif&quot;; font-size:11pt">
<a href=3D"mailto:[email protected]">firewall-=
[email protected]</a> [<a href=3D"mailto:firewall-wizar=
[email protected]">mailto:firewall-wizards-bounces@listserv.=
icsalabs.com</a>]
<b>On Behalf Of </b>Crispin Cowan<br>
<b>Sent:</b> Friday, July 05, 2013 12:04 PM<br>
<b>To:</b> Firewall Wizards Security Mailing List<br>
<b>Subject:</b> Re: [fw-wiz] DISA eliminating firewalls</span></p>
</div>
</div>
<p class=3D"MsoNormal">&nbsp;</p>
<div>
<div>
<p class=3D"MsoNormal"><span style=3D"font-family:&quot;Calibri&quot;,&quot=
;sans-serif&quot;">Firewalls are virtually guaranteed to disappear. The wri=
ting was on the wall the first time&nbsp;=93crunchy outside, gooey middle=
=94 was uttered. Smart phones and tablets dig the hole deeper, and
 BYOD is the nail in the coffin.</span></p>
</div>
<div>
<p class=3D"MsoNormal"><span style=3D"font-family:&quot;Calibri&quot;,&quot=
;sans-serif&quot;">&nbsp;</span></p>
</div>
<div>
<p class=3D"MsoNormal"><span style=3D"font-family:&quot;Calibri&quot;,&quot=
;sans-serif&quot;">You cannot protect your networks in a world full of smar=
t phones and tablets, owned by consumers, which must be allowed to connect =
to the network. The only thing you can do at that point
 is to stop trusting the network, and instead trust individual nodes, and u=
se encrypted channels (IPsec, SSL, whatever) between nodes that trust each =
other.</span></p>
</div>
<div>
<p class=3D"MsoNormal"><span style=3D"font-family:&quot;Calibri&quot;,&quot=
;sans-serif&quot;">&nbsp;</span></p>
</div>
<div>
<p class=3D"MsoNormal"><span style=3D"font-family:&quot;Calibri&quot;,&quot=
;sans-serif&quot;">When this will happen is far less clear, and it may be t=
hat DISA is a bit premature here. But this is coming, get used to it.</span=
></p>
</div>
<div>
<div>
<p class=3D"MsoNormal"><span style=3D"font-family:&quot;Calibri&quot;,&quot=
;sans-serif&quot;">&nbsp;</span></p>
</div>
<div>
<p class=3D"MsoNormal"><span style=3D"font-family:&quot;Calibri&quot;,&quot=
;sans-serif&quot;">Sent from Windows Mail</span></p>
</div>
<div>
<p class=3D"MsoNormal"><span style=3D"font-family:&quot;Calibri&quot;,&quot=
;sans-serif&quot;">&nbsp;</span></p>
</div>
</div>
<div>
<p class=3D"MsoNormal"><span style=3D"font-family:&quot;Calibri&quot;,&quot=
;sans-serif&quot;">&nbsp;</span></p>
</div>
</div>
</div>
</div>
</div>
</blockquote>
<blockquote type=3D"cite">
<div><span>_______________________________________________</span><br>
<span>firewall-wizards mailing list</span><br>
<span><a href=3D"mailto:[email protected]">firewall-wi=
[email protected]</a></span><br>
<span><a href=3D"https://listserv.icsalabs.com/mailman/listinfo/firewall-wi=
zards">https://listserv.icsalabs.com/mailman/listinfo/firewall-wizards</a><=
/span><br>
</div>
</blockquote>
<br>
<hr>
<font face=3D"Arial" color=3D"Gray" size=3D"1"><br>
This e-mail message, including any attachments, is for the sole use of the =
person to whom it has been sent, and may contain information that is confid=
ential or legally protected. If you are not the intended recipient or have =
received this message in error,
 you are not authorized to copy, distribute, or otherwise use this message =
or its attachments. Please notify the sender immediately by return e-mail a=
nd permanently delete this message and any attachments. Gartner makes no wa=
rranty that this e-mail is error
 or virus free.<br>
</font>
</body>
</html>

--_000_25D308BE2CEA4C45BECDB9C067C5DBDBgartnercom_--

--===============0826379384==
Content-Type: text/plain; charset="us-ascii"
MIME-Version: 1.0
Content-Transfer-Encoding: 7bit
Content-Disposition: inline

_______________________________________________
firewall-wizards mailing list
[email protected]
https://listserv.icsalabs.com/mailman/listinfo/firewall-wizards

--===============0826379384==--