Re: DISA eliminating firewalls

"Gumennik, Mark J." <[email protected]> Fri, 12 Jul 2013 14:26:04 +0000
Newsgroups gmane.comp.security.firewalls.wizards
Message-ID <[email protected]>
--===============0269940368==
Content-Language: en-US
Content-Type: multipart/alternative;
	boundary="_000_158ACD5E364C204A83FBC2B5DC130E441F0693EAIMCMBX04MITREOR_"

--_000_158ACD5E364C204A83FBC2B5DC130E441F0693EAIMCMBX04MITREOR_
Content-Type: text/plain; charset="us-ascii"
Content-Transfer-Encoding: quoted-printable

Take into consideration that DISA is a very large ISP and a huge bureaucrac=
y. Firewall going away from ISP? - What else is new? Big Bosses discussing =
things they don't understand with authority? - what else is new?
DISA has been trying to implement it ever since the AF installed a similar =
infrastructure, which lead to even more firewall implementations due to seg=
regation of functional networks (see the thread - Wi-Fi, phones, etc. need =
their own firewalled sub-netting if you properly designed your networks)
Firewalls evolving into more and more complex devices, incorporating IDS, I=
PS, VPN concentrators, etc. etc., but we still call them firewalls, whether=
 it's packet filter or an app proxy (all vendors actually claim nowadays th=
at they can do both - hmmm...). Call them whatever you want, but the functi=
onality stays. We all know that we can't fully protect our networks no matt=
er what we do; and the best we can do is to add layers of defense, not subt=
ract them; and the FW functionality is the main layer I can think of for a =
long time.
So sleep well Firewall Wizards, you job is safe and is a good one :)

      --    Mark


From: [email protected] [mailto:firewall-wizar=
[email protected]] On Behalf Of James Wright
Sent: Monday, July 08, 2013 4:14 PM
To: Firewall Wizards Security Mailing List
Cc: [email protected]
Subject: Re: [fw-wiz] DISA eliminating firewalls

Agreed, I also do not see them going away.  While BYOD is becoming a common=
 practice, so is network segregation, such as separate wifi networks dedica=
ted to personal devices.  Just because they need connectivity for their dev=
ice does not necessarily mean that it has to be direct connectivity to inte=
rnal resources and it does not mean that every employee/user needs that lev=
el of connectivity.  Vendors are getting better with the device VPN poducts=
 as a method of internal access, which can include an endpoint compliance s=
can.  This can ensure the device meets local policies (like not being on th=
e cell or other networks too, having AV (for what it's worth), or other sof=
tware/features).  Often times the VPN options include turning off split-tun=
neling (forcing all data traffic through the VPN tunnel), and other proxy t=
ype options.


Regards,
James


On Sun, Jul 7, 2013 at 12:46 AM, kent <[email protected]<mailto:kent@songbi=
rd.com>> wrote:
On 07/06/2013 08:55 AM, Crispin Cowan wrote:
> "What will happen when firewalls go away?" is a very good question, i
> don't have that answer. I simply assert that firewalls will go away,
> because they will become irrelevant. They are already barely relevant
> because of mobile devices. The threatscape is ignoring your firewall and
> walking straight through the front door attached to each individual
> worker in the form of a smart phone or a tablet. Not only do the users
> use them any way they want while away from the office, most of these
> devices are dual-homed to your network and a cellular network plumped
> right to the internet.
>
> It is neither my choice nor my wish that firewalls will go away, merely
> an inevitable consequence of pervasive mobile computing in the enterprise=
.
Firewalls will be with us for a long time to come.  Old threats don't
become irrelevant just because there are powerful new threats.

Kent
_______________________________________________
firewall-wizards mailing list
[email protected]<mailto:[email protected]=
alabs.com>
https://listserv.icsalabs.com/mailman/listinfo/firewall-wizards


--_000_158ACD5E364C204A83FBC2B5DC130E441F0693EAIMCMBX04MITREOR_
Content-Type: text/html; charset="us-ascii"
Content-Transfer-Encoding: quoted-printable

<html xmlns:v=3D"urn:schemas-microsoft-com:vml" xmlns:o=3D"urn:schemas-micr=
osoft-com:office:office" xmlns:w=3D"urn:schemas-microsoft-com:office:word" =
xmlns:m=3D"http://schemas.microsoft.com/office/2004/12/omml" xmlns=3D"http:=
//www.w3.org/TR/REC-html40">
<head>
<meta http-equiv=3D"Content-Type" content=3D"text/html; charset=3Dus-ascii"=
>
<meta name=3D"Generator" content=3D"Microsoft Word 14 (filtered medium)">
<style><!--
/* Font Definitions */
@font-face
	{font-family:Wingdings;
	panose-1:5 0 0 0 0 0 0 0 0 0;}
@font-face
	{font-family:Wingdings;
	panose-1:5 0 0 0 0 0 0 0 0 0;}
@font-face
	{font-family:Calibri;
	panose-1:2 15 5 2 2 2 4 3 2 4;}
@font-face
	{font-family:Tahoma;
	panose-1:2 11 6 4 3 5 4 4 2 4;}
/* Style Definitions */
p.MsoNormal, li.MsoNormal, div.MsoNormal
	{margin:0in;
	margin-bottom:.0001pt;
	font-size:12.0pt;
	font-family:"Times New Roman","serif";}
a:link, span.MsoHyperlink
	{mso-style-priority:99;
	color:blue;
	text-decoration:underline;}
a:visited, span.MsoHyperlinkFollowed
	{mso-style-priority:99;
	color:purple;
	text-decoration:underline;}
span.hoenzb
	{mso-style-name:hoenzb;}
span.EmailStyle18
	{mso-style-type:personal-reply;
	font-family:"Calibri","sans-serif";
	color:#1F497D;}
.MsoChpDefault
	{mso-style-type:export-only;
	font-family:"Calibri","sans-serif";}
@page WordSection1
	{size:8.5in 11.0in;
	margin:1.0in 1.0in 1.0in 1.0in;}
div.WordSection1
	{page:WordSection1;}
--></style><!--[if gte mso 9]><xml>
<o:shapedefaults v:ext=3D"edit" spidmax=3D"1026" />
</xml><![endif]--><!--[if gte mso 9]><xml>
<o:shapelayout v:ext=3D"edit">
<o:idmap v:ext=3D"edit" data=3D"1" />
</o:shapelayout></xml><![endif]-->
</head>
<body lang=3D"EN-US" link=3D"blue" vlink=3D"purple">
<div class=3D"WordSection1">
<p class=3D"MsoNormal"><span style=3D"font-size:11.0pt;font-family:&quot;Ca=
libri&quot;,&quot;sans-serif&quot;;color:#1F497D">Take into consideration t=
hat DISA is a very large ISP and a huge bureaucracy. Firewall going away fr=
om ISP? &#8211; What else is new? Big Bosses discussing things
 they don&#8217;t understand with authority? &#8211; what else is new?<o:p>=
</o:p></span></p>
<p class=3D"MsoNormal"><span style=3D"font-size:11.0pt;font-family:&quot;Ca=
libri&quot;,&quot;sans-serif&quot;;color:#1F497D">DISA has been trying to i=
mplement it ever since the AF installed a similar infrastructure, which lea=
d to even more firewall implementations due to segregation
 of functional networks (see the thread &#8211; Wi-Fi, phones, etc. need th=
eir own firewalled sub-netting if you properly designed your networks)<o:p>=
</o:p></span></p>
<p class=3D"MsoNormal"><span style=3D"font-size:11.0pt;font-family:&quot;Ca=
libri&quot;,&quot;sans-serif&quot;;color:#1F497D">Firewalls evolving into m=
ore and more complex devices, incorporating IDS, IPS, VPN concentrators, et=
c. etc., but we still call them firewalls, whether it&#8217;s
 packet filter or an app proxy (all vendors actually claim nowadays that th=
ey can do both &#8211; hmmm&#8230;). Call them whatever you want, but the f=
unctionality stays. We all know that we can&#8217;t fully protect our netwo=
rks no matter what we do; and the best we can do is
 to add layers of defense, not subtract them; and the FW functionality is t=
he main layer I can think of for a long time.
<o:p></o:p></span></p>
<p class=3D"MsoNormal"><span style=3D"font-size:11.0pt;font-family:&quot;Ca=
libri&quot;,&quot;sans-serif&quot;;color:#1F497D">So sleep well Firewall Wi=
zards, you job is safe and is a good one
</span><span style=3D"font-size:11.0pt;font-family:Wingdings;color:#1F497D"=
>J</span><span style=3D"font-size:11.0pt;font-family:&quot;Calibri&quot;,&q=
uot;sans-serif&quot;;color:#1F497D"><o:p></o:p></span></p>
<p class=3D"MsoNormal"><span style=3D"font-size:11.0pt;font-family:&quot;Ca=
libri&quot;,&quot;sans-serif&quot;;color:#1F497D"><o:p>&nbsp;</o:p></span><=
/p>
<p class=3D"MsoNormal"><span style=3D"font-size:11.0pt;font-family:&quot;Ar=
ial&quot;,&quot;sans-serif&quot;;color:black">&nbsp;&nbsp;&nbsp;&nbsp; &nbs=
p;</span><span style=3D"font-size:11.0pt;font-family:&quot;Calibri&quot;,&q=
uot;sans-serif&quot;;color:black">--&nbsp;&nbsp;&nbsp; Mark&nbsp;<o:p></o:p=
></span></p>
<p class=3D"MsoNormal"><span style=3D"font-size:11.0pt;font-family:&quot;Ca=
libri&quot;,&quot;sans-serif&quot;;color:#244061"><o:p>&nbsp;</o:p></span><=
/p>
<p class=3D"MsoNormal"><span style=3D"font-size:11.0pt;font-family:&quot;Ca=
libri&quot;,&quot;sans-serif&quot;;color:#1F497D"><o:p>&nbsp;</o:p></span><=
/p>
<p class=3D"MsoNormal" style=3D"margin-left:.5in"><b><span style=3D"font-si=
ze:10.0pt;font-family:&quot;Tahoma&quot;,&quot;sans-serif&quot;">From:</spa=
n></b><span style=3D"font-size:10.0pt;font-family:&quot;Tahoma&quot;,&quot;=
sans-serif&quot;"> [email protected] [mailto:f=
[email protected]]
<b>On Behalf Of </b>James Wright<br>
<b>Sent:</b> Monday, July 08, 2013 4:14 PM<br>
<b>To:</b> Firewall Wizards Security Mailing List<br>
<b>Cc:</b> [email protected]<br>
<b>Subject:</b> Re: [fw-wiz] DISA eliminating firewalls<o:p></o:p></span></=
p>
<p class=3D"MsoNormal" style=3D"margin-left:.5in"><o:p>&nbsp;</o:p></p>
<div>
<p class=3D"MsoNormal" style=3D"margin-left:.5in">Agreed, I also do not see=
 them going away. &nbsp;While BYOD is becoming a common practice, so is net=
work segregation, such as separate wifi networks dedicated to personal devi=
ces. &nbsp;Just because they need connectivity
 for their device does not necessarily mean that it has to be direct connec=
tivity to internal resources and it does not mean that every employee/user =
needs that level of connectivity. &nbsp;Vendors are getting better with the=
 device VPN poducts as a method of internal
 access, which can include an endpoint compliance scan. &nbsp;This can ensu=
re the device meets local policies (like not being on the cell or other net=
works too, having AV (for what it's worth), or other software/features). &n=
bsp;Often times the VPN options include turning
 off split-tunneling (forcing all data traffic through the VPN tunnel), and=
 other proxy type options.<o:p></o:p></p>
<div>
<p class=3D"MsoNormal" style=3D"margin-left:.5in"><o:p>&nbsp;</o:p></p>
</div>
<div>
<p class=3D"MsoNormal" style=3D"margin-left:.5in"><o:p>&nbsp;</o:p></p>
</div>
<div>
<p class=3D"MsoNormal" style=3D"margin-left:.5in">Regards,<br>
James<o:p></o:p></p>
</div>
<div>
<p class=3D"MsoNormal" style=3D"margin-left:.5in"><o:p>&nbsp;</o:p></p>
</div>
</div>
<div>
<p class=3D"MsoNormal" style=3D"mso-margin-top-alt:0in;margin-right:0in;mar=
gin-bottom:12.0pt;margin-left:.5in">
<o:p>&nbsp;</o:p></p>
<div>
<p class=3D"MsoNormal" style=3D"margin-left:.5in">On Sun, Jul 7, 2013 at 12=
:46 AM, kent &lt;<a href=3D"mailto:[email protected]" target=3D"_blank">ken=
[email protected]</a>&gt; wrote:<o:p></o:p></p>
<div>
<p class=3D"MsoNormal" style=3D"mso-margin-top-alt:0in;margin-right:0in;mar=
gin-bottom:12.0pt;margin-left:.5in">
On 07/06/2013 08:55 AM, Crispin Cowan wrote:<br>
&gt; &#8220;What will happen when firewalls go away?&#8221; is a very good =
question, i<br>
&gt; don&#8217;t have that answer. I simply assert that firewalls will go a=
way,<br>
&gt; because they will become irrelevant. They are already barely relevant<=
br>
&gt; because of mobile devices. The threatscape is ignoring your firewall a=
nd<br>
&gt; walking straight through the front door attached to each individual<br=
>
&gt; worker in the form of a smart phone or a tablet. Not only do the users=
<br>
&gt; use them any way they want while away from the office, most of these<b=
r>
&gt; devices are dual-homed to your network and a cellular network plumped<=
br>
&gt; right to the internet.<br>
&gt;<br>
&gt; It is neither my choice nor my wish that firewalls will go away, merel=
y<br>
&gt; an inevitable consequence of pervasive mobile computing in the enterpr=
ise.<o:p></o:p></p>
</div>
<p class=3D"MsoNormal" style=3D"margin-left:.5in">Firewalls will be with us=
 for a long time to come. &nbsp;Old threats don't<br>
become irrelevant just because there are powerful new threats.<br>
<span style=3D"color:#888888"><br>
<span class=3D"hoenzb">Kent</span></span><o:p></o:p></p>
<div>
<div>
<p class=3D"MsoNormal" style=3D"margin-left:.5in">_________________________=
______________________<br>
firewall-wizards mailing list<br>
<a href=3D"mailto:[email protected]">firewall-wizards@=
listserv.icsalabs.com</a><br>
<a href=3D"https://listserv.icsalabs.com/mailman/listinfo/firewall-wizards"=
 target=3D"_blank">https://listserv.icsalabs.com/mailman/listinfo/firewall-=
wizards</a><o:p></o:p></p>
</div>
</div>
</div>
<p class=3D"MsoNormal" style=3D"margin-left:.5in"><o:p>&nbsp;</o:p></p>
</div>
</div>
</body>
</html>

--_000_158ACD5E364C204A83FBC2B5DC130E441F0693EAIMCMBX04MITREOR_--

--===============0269940368==
Content-Type: text/plain; charset="us-ascii"
MIME-Version: 1.0
Content-Transfer-Encoding: 7bit
Content-Disposition: inline

_______________________________________________
firewall-wizards mailing list
[email protected]
https://listserv.icsalabs.com/mailman/listinfo/firewall-wizards

--===============0269940368==--