Re: DISA eliminating firewalls
James Wright <[email protected]> Mon, 8 Jul 2013 16:14:15 -0400
| Newsgroups | gmane.comp.security.firewalls.wizards |
|---|---|
| Message-ID | <CAKpcs8TWe5htFipdyJiprLJybQJqi9YuoeyTMtKgYOuWSajWCw@mail.gmail.com> |
--===============1656941173== Content-Type: multipart/alternative; boundary=089e016351d047af9f04e105b039 --089e016351d047af9f04e105b039 Content-Type: text/plain; charset=windows-1252 Content-Transfer-Encoding: quoted-printable Agreed, I also do not see them going away. While BYOD is becoming a common practice, so is network segregation, such as separate wifi networks dedicated to personal devices. Just because they need connectivity for their device does not necessarily mean that it has to be direct connectivity to internal resources and it does not mean that every employee/user needs that level of connectivity. Vendors are getting better with the device VPN poducts as a method of internal access, which can include an endpoint compliance scan. This can ensure the device meets local policies (like not being on the cell or other networks too, having AV (for what it's worth), or other software/features). Often times the VPN options include turning off split-tunneling (forcing all data traffic through the VPN tunnel), and other proxy type options. Regards, James On Sun, Jul 7, 2013 at 12:46 AM, kent <[email protected]> wrote: > On 07/06/2013 08:55 AM, Crispin Cowan wrote: > > =93What will happen when firewalls go away?=94 is a very good question,= i > > don=92t have that answer. I simply assert that firewalls will go away, > > because they will become irrelevant. They are already barely relevant > > because of mobile devices. The threatscape is ignoring your firewall an= d > > walking straight through the front door attached to each individual > > worker in the form of a smart phone or a tablet. Not only do the users > > use them any way they want while away from the office, most of these > > devices are dual-homed to your network and a cellular network plumped > > right to the internet. > > > > It is neither my choice nor my wish that firewalls will go away, merely > > an inevitable consequence of pervasive mobile computing in the > enterprise. > > Firewalls will be with us for a long time to come. Old threats don't > become irrelevant just because there are powerful new threats. > > Kent > _______________________________________________ > firewall-wizards mailing list > [email protected] > https://listserv.icsalabs.com/mailman/listinfo/firewall-wizards > --089e016351d047af9f04e105b039 Content-Type: text/html; charset=windows-1252 Content-Transfer-Encoding: quoted-printable <div dir=3D"ltr">Agreed, I also do not see them going away. =A0While BYOD i= s becoming a common practice, so is network segregation, such as separate w= ifi networks dedicated to personal devices. =A0Just because they need conne= ctivity for their device does not necessarily mean that it has to be direct= connectivity to internal resources and it does not mean that every employe= e/user needs that level of connectivity. =A0Vendors are getting better with= the device VPN poducts as a method of internal access, which can include a= n endpoint compliance scan. =A0This can ensure the device meets local polic= ies (like not being on the cell or other networks too, having AV (for what = it's worth), or other software/features). =A0Often times the VPN option= s include turning off split-tunneling (forcing all data traffic through the= VPN tunnel), and other proxy type options.<div> <br></div><div><br></div><div>Regards,<br>James</div><div><br></div></div><= div class=3D"gmail_extra"><br><br><div class=3D"gmail_quote">On Sun, Jul 7,= 2013 at 12:46 AM, kent <span dir=3D"ltr"><<a href=3D"mailto:kent@songbi= rd.com" target=3D"_blank">[email protected]</a>></span> wrote:<br> <blockquote class=3D"gmail_quote" style=3D"margin:0 0 0 .8ex;border-left:1p= x #ccc solid;padding-left:1ex"><div class=3D"im">On 07/06/2013 08:55 AM, Cr= ispin Cowan wrote:<br> > =93What will happen when firewalls go away?=94 is a very good question= , i<br> > don=92t have that answer. I simply assert that firewalls will go away,= <br> > because they will become irrelevant. They are already barely relevant<= br> > because of mobile devices. The threatscape is ignoring your firewall a= nd<br> > walking straight through the front door attached to each individual<br= > > worker in the form of a smart phone or a tablet. Not only do the users= <br> > use them any way they want while away from the office, most of these<b= r> > devices are dual-homed to your network and a cellular network plumped<= br> > right to the internet.<br> ><br> > It is neither my choice nor my wish that firewalls will go away, merel= y<br> > an inevitable consequence of pervasive mobile computing in the enterpr= ise.<br> <br> </div>Firewalls will be with us for a long time to come. =A0Old threats don= 't<br> become irrelevant just because there are powerful new threats.<br> <span class=3D"HOEnZb"><font color=3D"#888888"><br> Kent<br> </font></span><div class=3D"HOEnZb"><div class=3D"h5">_____________________= __________________________<br> firewall-wizards mailing list<br> <a href=3D"mailto:[email protected]">firewall-wizards@= listserv.icsalabs.com</a><br> <a href=3D"https://listserv.icsalabs.com/mailman/listinfo/firewall-wizards"= target=3D"_blank">https://listserv.icsalabs.com/mailman/listinfo/firewall-= wizards</a><br> </div></div></blockquote></div><br></div> --089e016351d047af9f04e105b039-- --===============1656941173== Content-Type: text/plain; charset="us-ascii" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit Content-Disposition: inline _______________________________________________ firewall-wizards mailing list [email protected] https://listserv.icsalabs.com/mailman/listinfo/firewall-wizards --===============1656941173==--