Re: DISA eliminating firewalls
"Gumennik, Mark J." <[email protected]> Fri, 12 Jul 2013 14:26:04 +0000
| Newsgroups | gmane.comp.security.firewalls.wizards |
|---|---|
| Message-ID | <[email protected]> |
--===============0269940368==
Content-Language: en-US
Content-Type: multipart/alternative;
boundary="_000_158ACD5E364C204A83FBC2B5DC130E441F0693EAIMCMBX04MITREOR_"
--_000_158ACD5E364C204A83FBC2B5DC130E441F0693EAIMCMBX04MITREOR_
Content-Type: text/plain; charset="us-ascii"
Content-Transfer-Encoding: quoted-printable
Take into consideration that DISA is a very large ISP and a huge bureaucrac=
y. Firewall going away from ISP? - What else is new? Big Bosses discussing =
things they don't understand with authority? - what else is new?
DISA has been trying to implement it ever since the AF installed a similar =
infrastructure, which lead to even more firewall implementations due to seg=
regation of functional networks (see the thread - Wi-Fi, phones, etc. need =
their own firewalled sub-netting if you properly designed your networks)
Firewalls evolving into more and more complex devices, incorporating IDS, I=
PS, VPN concentrators, etc. etc., but we still call them firewalls, whether=
it's packet filter or an app proxy (all vendors actually claim nowadays th=
at they can do both - hmmm...). Call them whatever you want, but the functi=
onality stays. We all know that we can't fully protect our networks no matt=
er what we do; and the best we can do is to add layers of defense, not subt=
ract them; and the FW functionality is the main layer I can think of for a =
long time.
So sleep well Firewall Wizards, you job is safe and is a good one :)
-- Mark
From: [email protected] [mailto:firewall-wizar=
[email protected]] On Behalf Of James Wright
Sent: Monday, July 08, 2013 4:14 PM
To: Firewall Wizards Security Mailing List
Cc: [email protected]
Subject: Re: [fw-wiz] DISA eliminating firewalls
Agreed, I also do not see them going away. While BYOD is becoming a common=
practice, so is network segregation, such as separate wifi networks dedica=
ted to personal devices. Just because they need connectivity for their dev=
ice does not necessarily mean that it has to be direct connectivity to inte=
rnal resources and it does not mean that every employee/user needs that lev=
el of connectivity. Vendors are getting better with the device VPN poducts=
as a method of internal access, which can include an endpoint compliance s=
can. This can ensure the device meets local policies (like not being on th=
e cell or other networks too, having AV (for what it's worth), or other sof=
tware/features). Often times the VPN options include turning off split-tun=
neling (forcing all data traffic through the VPN tunnel), and other proxy t=
ype options.
Regards,
James
On Sun, Jul 7, 2013 at 12:46 AM, kent <[email protected]<mailto:kent@songbi=
rd.com>> wrote:
On 07/06/2013 08:55 AM, Crispin Cowan wrote:
> "What will happen when firewalls go away?" is a very good question, i
> don't have that answer. I simply assert that firewalls will go away,
> because they will become irrelevant. They are already barely relevant
> because of mobile devices. The threatscape is ignoring your firewall and
> walking straight through the front door attached to each individual
> worker in the form of a smart phone or a tablet. Not only do the users
> use them any way they want while away from the office, most of these
> devices are dual-homed to your network and a cellular network plumped
> right to the internet.
>
> It is neither my choice nor my wish that firewalls will go away, merely
> an inevitable consequence of pervasive mobile computing in the enterprise=
.
Firewalls will be with us for a long time to come. Old threats don't
become irrelevant just because there are powerful new threats.
Kent
_______________________________________________
firewall-wizards mailing list
[email protected]<mailto:[email protected]=
alabs.com>
https://listserv.icsalabs.com/mailman/listinfo/firewall-wizards
--_000_158ACD5E364C204A83FBC2B5DC130E441F0693EAIMCMBX04MITREOR_
Content-Type: text/html; charset="us-ascii"
Content-Transfer-Encoding: quoted-printable
<html xmlns:v=3D"urn:schemas-microsoft-com:vml" xmlns:o=3D"urn:schemas-micr=
osoft-com:office:office" xmlns:w=3D"urn:schemas-microsoft-com:office:word" =
xmlns:m=3D"http://schemas.microsoft.com/office/2004/12/omml" xmlns=3D"http:=
//www.w3.org/TR/REC-html40">
<head>
<meta http-equiv=3D"Content-Type" content=3D"text/html; charset=3Dus-ascii"=
>
<meta name=3D"Generator" content=3D"Microsoft Word 14 (filtered medium)">
<style><!--
/* Font Definitions */
@font-face
{font-family:Wingdings;
panose-1:5 0 0 0 0 0 0 0 0 0;}
@font-face
{font-family:Wingdings;
panose-1:5 0 0 0 0 0 0 0 0 0;}
@font-face
{font-family:Calibri;
panose-1:2 15 5 2 2 2 4 3 2 4;}
@font-face
{font-family:Tahoma;
panose-1:2 11 6 4 3 5 4 4 2 4;}
/* Style Definitions */
p.MsoNormal, li.MsoNormal, div.MsoNormal
{margin:0in;
margin-bottom:.0001pt;
font-size:12.0pt;
font-family:"Times New Roman","serif";}
a:link, span.MsoHyperlink
{mso-style-priority:99;
color:blue;
text-decoration:underline;}
a:visited, span.MsoHyperlinkFollowed
{mso-style-priority:99;
color:purple;
text-decoration:underline;}
span.hoenzb
{mso-style-name:hoenzb;}
span.EmailStyle18
{mso-style-type:personal-reply;
font-family:"Calibri","sans-serif";
color:#1F497D;}
.MsoChpDefault
{mso-style-type:export-only;
font-family:"Calibri","sans-serif";}
@page WordSection1
{size:8.5in 11.0in;
margin:1.0in 1.0in 1.0in 1.0in;}
div.WordSection1
{page:WordSection1;}
--></style><!--[if gte mso 9]><xml>
<o:shapedefaults v:ext=3D"edit" spidmax=3D"1026" />
</xml><![endif]--><!--[if gte mso 9]><xml>
<o:shapelayout v:ext=3D"edit">
<o:idmap v:ext=3D"edit" data=3D"1" />
</o:shapelayout></xml><![endif]-->
</head>
<body lang=3D"EN-US" link=3D"blue" vlink=3D"purple">
<div class=3D"WordSection1">
<p class=3D"MsoNormal"><span style=3D"font-size:11.0pt;font-family:"Ca=
libri","sans-serif";color:#1F497D">Take into consideration t=
hat DISA is a very large ISP and a huge bureaucracy. Firewall going away fr=
om ISP? – What else is new? Big Bosses discussing things
they don’t understand with authority? – what else is new?<o:p>=
</o:p></span></p>
<p class=3D"MsoNormal"><span style=3D"font-size:11.0pt;font-family:"Ca=
libri","sans-serif";color:#1F497D">DISA has been trying to i=
mplement it ever since the AF installed a similar infrastructure, which lea=
d to even more firewall implementations due to segregation
of functional networks (see the thread – Wi-Fi, phones, etc. need th=
eir own firewalled sub-netting if you properly designed your networks)<o:p>=
</o:p></span></p>
<p class=3D"MsoNormal"><span style=3D"font-size:11.0pt;font-family:"Ca=
libri","sans-serif";color:#1F497D">Firewalls evolving into m=
ore and more complex devices, incorporating IDS, IPS, VPN concentrators, et=
c. etc., but we still call them firewalls, whether it’s
packet filter or an app proxy (all vendors actually claim nowadays that th=
ey can do both – hmmm…). Call them whatever you want, but the f=
unctionality stays. We all know that we can’t fully protect our netwo=
rks no matter what we do; and the best we can do is
to add layers of defense, not subtract them; and the FW functionality is t=
he main layer I can think of for a long time.
<o:p></o:p></span></p>
<p class=3D"MsoNormal"><span style=3D"font-size:11.0pt;font-family:"Ca=
libri","sans-serif";color:#1F497D">So sleep well Firewall Wi=
zards, you job is safe and is a good one
</span><span style=3D"font-size:11.0pt;font-family:Wingdings;color:#1F497D"=
>J</span><span style=3D"font-size:11.0pt;font-family:"Calibri",&q=
uot;sans-serif";color:#1F497D"><o:p></o:p></span></p>
<p class=3D"MsoNormal"><span style=3D"font-size:11.0pt;font-family:"Ca=
libri","sans-serif";color:#1F497D"><o:p> </o:p></span><=
/p>
<p class=3D"MsoNormal"><span style=3D"font-size:11.0pt;font-family:"Ar=
ial","sans-serif";color:black"> &nbs=
p;</span><span style=3D"font-size:11.0pt;font-family:"Calibri",&q=
uot;sans-serif";color:black">-- Mark <o:p></o:p=
></span></p>
<p class=3D"MsoNormal"><span style=3D"font-size:11.0pt;font-family:"Ca=
libri","sans-serif";color:#244061"><o:p> </o:p></span><=
/p>
<p class=3D"MsoNormal"><span style=3D"font-size:11.0pt;font-family:"Ca=
libri","sans-serif";color:#1F497D"><o:p> </o:p></span><=
/p>
<p class=3D"MsoNormal" style=3D"margin-left:.5in"><b><span style=3D"font-si=
ze:10.0pt;font-family:"Tahoma","sans-serif"">From:</spa=
n></b><span style=3D"font-size:10.0pt;font-family:"Tahoma","=
sans-serif""> [email protected] [mailto:f=
[email protected]]
<b>On Behalf Of </b>James Wright<br>
<b>Sent:</b> Monday, July 08, 2013 4:14 PM<br>
<b>To:</b> Firewall Wizards Security Mailing List<br>
<b>Cc:</b> [email protected]<br>
<b>Subject:</b> Re: [fw-wiz] DISA eliminating firewalls<o:p></o:p></span></=
p>
<p class=3D"MsoNormal" style=3D"margin-left:.5in"><o:p> </o:p></p>
<div>
<p class=3D"MsoNormal" style=3D"margin-left:.5in">Agreed, I also do not see=
them going away. While BYOD is becoming a common practice, so is net=
work segregation, such as separate wifi networks dedicated to personal devi=
ces. Just because they need connectivity
for their device does not necessarily mean that it has to be direct connec=
tivity to internal resources and it does not mean that every employee/user =
needs that level of connectivity. Vendors are getting better with the=
device VPN poducts as a method of internal
access, which can include an endpoint compliance scan. This can ensu=
re the device meets local policies (like not being on the cell or other net=
works too, having AV (for what it's worth), or other software/features). &n=
bsp;Often times the VPN options include turning
off split-tunneling (forcing all data traffic through the VPN tunnel), and=
other proxy type options.<o:p></o:p></p>
<div>
<p class=3D"MsoNormal" style=3D"margin-left:.5in"><o:p> </o:p></p>
</div>
<div>
<p class=3D"MsoNormal" style=3D"margin-left:.5in"><o:p> </o:p></p>
</div>
<div>
<p class=3D"MsoNormal" style=3D"margin-left:.5in">Regards,<br>
James<o:p></o:p></p>
</div>
<div>
<p class=3D"MsoNormal" style=3D"margin-left:.5in"><o:p> </o:p></p>
</div>
</div>
<div>
<p class=3D"MsoNormal" style=3D"mso-margin-top-alt:0in;margin-right:0in;mar=
gin-bottom:12.0pt;margin-left:.5in">
<o:p> </o:p></p>
<div>
<p class=3D"MsoNormal" style=3D"margin-left:.5in">On Sun, Jul 7, 2013 at 12=
:46 AM, kent <<a href=3D"mailto:[email protected]" target=3D"_blank">ken=
[email protected]</a>> wrote:<o:p></o:p></p>
<div>
<p class=3D"MsoNormal" style=3D"mso-margin-top-alt:0in;margin-right:0in;mar=
gin-bottom:12.0pt;margin-left:.5in">
On 07/06/2013 08:55 AM, Crispin Cowan wrote:<br>
> “What will happen when firewalls go away?” is a very good =
question, i<br>
> don’t have that answer. I simply assert that firewalls will go a=
way,<br>
> because they will become irrelevant. They are already barely relevant<=
br>
> because of mobile devices. The threatscape is ignoring your firewall a=
nd<br>
> walking straight through the front door attached to each individual<br=
>
> worker in the form of a smart phone or a tablet. Not only do the users=
<br>
> use them any way they want while away from the office, most of these<b=
r>
> devices are dual-homed to your network and a cellular network plumped<=
br>
> right to the internet.<br>
><br>
> It is neither my choice nor my wish that firewalls will go away, merel=
y<br>
> an inevitable consequence of pervasive mobile computing in the enterpr=
ise.<o:p></o:p></p>
</div>
<p class=3D"MsoNormal" style=3D"margin-left:.5in">Firewalls will be with us=
for a long time to come. Old threats don't<br>
become irrelevant just because there are powerful new threats.<br>
<span style=3D"color:#888888"><br>
<span class=3D"hoenzb">Kent</span></span><o:p></o:p></p>
<div>
<div>
<p class=3D"MsoNormal" style=3D"margin-left:.5in">_________________________=
______________________<br>
firewall-wizards mailing list<br>
<a href=3D"mailto:[email protected]">firewall-wizards@=
listserv.icsalabs.com</a><br>
<a href=3D"https://listserv.icsalabs.com/mailman/listinfo/firewall-wizards"=
target=3D"_blank">https://listserv.icsalabs.com/mailman/listinfo/firewall-=
wizards</a><o:p></o:p></p>
</div>
</div>
</div>
<p class=3D"MsoNormal" style=3D"margin-left:.5in"><o:p> </o:p></p>
</div>
</div>
</body>
</html>
--_000_158ACD5E364C204A83FBC2B5DC130E441F0693EAIMCMBX04MITREOR_--
--===============0269940368==
Content-Type: text/plain; charset="us-ascii"
MIME-Version: 1.0
Content-Transfer-Encoding: 7bit
Content-Disposition: inline
_______________________________________________
firewall-wizards mailing list
[email protected]
https://listserv.icsalabs.com/mailman/listinfo/firewall-wizards
--===============0269940368==--