Re: Quiet
David Hills <[email protected]> Tue, 24 Jun 2014 14:05:28 +1200
| Newsgroups | gmane.comp.security.firewalls.wizards |
|---|---|
| Message-ID | <CAMQCHecXMb_qnUUvzS=id4Jr-3NberWm+7OofFx3ex+Mp9p9qw@mail.gmail.com> |
--===============0118272959== Content-Type: multipart/alternative; boundary=089e013c6d9ec95fff04fc8b6421 --089e013c6d9ec95fff04fc8b6421 Content-Type: text/plain; charset=UTF-8 Okay, I'll bite. > Thoughts on IPv6? You mean you aren't doing this yet? You're still using Windows XP and Fax as well, right? Platforms like the XBox One are already using IPv6 almost exclusively for P2P communications. Even my 3 year old printer which barely does WiFi reached out for DHCPv6 and gave itself an IP address when V6 was turned on at home. > Thoughts on "Cloud Firewalls?" I always use Cloud firewalls to protect my cloud assets. Otherwise those cloud bad actors might cloud my cloud product. My real IT though, uses real firewalls. Physical, Virtual, On-Site or in the Datacenter, frankly I don't care. But being "VMX" doesn't make you partly cloudy with a chance of rain. > Thoughts on Web Application Firewalls? If they serve a purpose, SURE! They make great SSL offloadning and Load Balancing appliances. Wherever I can use the PCIDSS budget from the security team to make my customer experience better, that can't be a bad thing, right? Doesn't reduce the need for good code and server patching though. > 1. Have any of you used the IPv6 IPSEC equivalent yet? Tunnel or transport mode? Vendor hardware? Difficulties? Vendors that don't have IPv6 hardware in at least their ISP / Datacenter products are probably looking at some hard times ahead. Most of the u > 2. I've pondered a cloud based service for web acceleration/filtering. Perhaps it would use Riverbeds for bandwidth optimization via compression, dedupe, etc....? Anything like that out there? CloudFlare? Akamai? I think the Microsoft Azure CDN even offers much of this. The advantage in context for this list? Takes your IPv4 only Datacenter provider and makes your website IPv6 without you evening noticing. Woo! > 3. If it doesn't do WAP, then it's an old fashioned firewall--and quite possibly obsolete. These days, the firewall has to encompass the whole stack (except layer 8--the user). I guess you could make specific cases like for networks that don't exchange HTTP/S traffic. But seriously, if your firewall doesn't understand the protocols it is passing, if it doesn't enforce RFCs to some extent, if it doesn't do sanity checking on bounds, and true protocol inspection... then what is it doing? :-) UInless you've been asleep and you're still buying Cisco - all the big network security vendors have moved to this model. Fortinet barely advertise themselves as being a firewall anymore, it's all about "Application Control". In their case, they also have full parity in their UTM between both IPv4 and IPv6. It's a brave new world. So, my question then - Who's doing VoIP over IPv6? Are you seeing advantages once we get NAT out of the way? David On 24 June 2014 05:16, Paul D. Robertson <[email protected]> wrote: > It's quiet here- I'd like to stir up some discussion... > > Thoughts on IPv6? > Thoughts on "Cloud Firewalls?" > Thoughts on Web Application Firewalls? > > Paul > _______________________________________________ > firewall-wizards mailing list > [email protected] > https://listserv.icsalabs.com/mailman/listinfo/firewall-wizards > --089e013c6d9ec95fff04fc8b6421 Content-Type: text/html; charset=UTF-8 Content-Transfer-Encoding: quoted-printable <div dir=3D"ltr">Okay, I'll bite.<div><br></div><div><span style=3D"fon= t-family:arial,sans-serif;font-size:13px">> Thoughts on IPv6?</span></di= v><div>You mean you aren't doing this yet? You're still using Windo= ws XP and Fax as well, right?</div> <div><br></div><div>Platforms like the XBox One are already using IPv6 almo= st exclusively for P2P communications. Even my 3 year old printer which bar= ely does WiFi reached out for DHCPv6 and gave itself an IP address when V6 = was turned on at home.</div> <div><br><span style=3D"font-family:arial,sans-serif;font-size:13px">> T= houghts on "Cloud Firewalls?"</span></div><div>I always use Cloud= firewalls to protect my cloud assets. Otherwise those cloud bad actors mig= ht cloud my cloud product.</div> <div><br></div><div>My real IT though, uses real firewalls. Physical, Virtu= al, On-Site or in the Datacenter, frankly I don't care. But being "= ;VMX" doesn't make you partly cloudy with a chance of rain.</div> <div><br><span style=3D"font-family:arial,sans-serif;font-size:13px">> T= houghts on Web Application Firewalls?</span><br style=3D"font-family:arial,= sans-serif;font-size:13px"></div><div><span style=3D"font-family:arial,sans= -serif;font-size:13px">If they serve a purpose, SURE! They make great SSL o= ffloadning and Load Balancing appliances. Wherever I can use the PCIDSS bud= get from the security team to make my customer experience better, that can&= #39;t be a bad thing, right?</span></div> <div><span style=3D"font-family:arial,sans-serif;font-size:13px"><br></span= ></div><div><span style=3D"font-family:arial,sans-serif;font-size:13px">Doe= sn't reduce the need for good code and server patching though.</span></= div> <div><span style=3D"font-family:arial,sans-serif;font-size:13px"><br></span= ></div><div><span style=3D"font-family:arial,sans-serif;font-size:13px">>= ; 1. Have any of you used the IPv6 IPSEC equivalent yet? =C2=A0Tunnel or tr= ansport mode? =C2=A0Vendor hardware? =C2=A0Difficulties?</span></div> <div>Vendors that don't have IPv6 hardware in at least their ISP / Data= center products are probably looking at some hard times ahead. Most of the = u<br style=3D"font-family:arial,sans-serif;font-size:13px"><br style=3D"fon= t-family:arial,sans-serif;font-size:13px"> <span style=3D"font-family:arial,sans-serif;font-size:13px">> 2. =C2=A0I= 've pondered a cloud based service for web acceleration/filtering. =C2= =A0Perhaps it would use Riverbeds for bandwidth optimization via compressio= n, dedupe, etc....? =C2=A0Anything like that out there?</span></div> <div>CloudFlare? Akamai? I think the Microsoft Azure CDN even offers much o= f this. The advantage in context for this list? Takes your IPv4 only Datace= nter provider and makes your website IPv6 without you evening noticing. Woo= !<br style=3D"font-family:arial,sans-serif;font-size:13px"> <br style=3D"font-family:arial,sans-serif;font-size:13px"><span style=3D"fo= nt-family:arial,sans-serif;font-size:13px">> 3. =C2=A0If it doesn't = do WAP, then it's an old fashioned firewall--and quite possibly obsolet= e. =C2=A0These days, the firewall has to encompass the whole stack (except = layer 8--the user). =C2=A0I guess you could make specific cases like for ne= tworks that don't exchange HTTP/S traffic. =C2=A0But seriously, if your= firewall doesn't understand the protocols it is passing, if it doesn&#= 39;t enforce RFCs to some extent, if it doesn't do sanity checking on b= ounds, and true protocol inspection... then what is it doing? =C2=A0:-)</sp= an><span style=3D"font-family:arial,sans-serif;font-size:13px"><br> </span></div><div><span style=3D"font-family:arial,sans-serif;font-size:13p= x">UInless you've been asleep and you're still buying Cisco - all t= he big network security vendors have moved to this model. Fortinet barely a= dvertise themselves as being a firewall anymore, it's all about "A= pplication Control". In their case, they also have full parity in thei= r UTM between both IPv4 and IPv6.=C2=A0</span></div> <div><span style=3D"font-family:arial,sans-serif;font-size:13px"><br></span= ></div><div><span style=3D"font-family:arial,sans-serif;font-size:13px">It&= #39;s a brave new world.</span></div><div><span style=3D"font-family:arial,= sans-serif;font-size:13px"><br> </span></div><div><span style=3D"font-family:arial,sans-serif;font-size:13p= x">So, my question then - Who's doing VoIP over IPv6? Are you seeing ad= vantages once we get NAT out of the way?</span></div><div><span style=3D"fo= nt-family:arial,sans-serif;font-size:13px"><br> </span></div><div><span style=3D"font-family:arial,sans-serif;font-size:13p= x">David</span></div><div><span style=3D"font-family:arial,sans-serif;font-= size:13px"><br></span></div></div><div class=3D"gmail_extra"><br><br><div c= lass=3D"gmail_quote"> On 24 June 2014 05:16, Paul D. Robertson <span dir=3D"ltr"><<a href=3D"m= ailto:[email protected]" target=3D"_blank">[email protected]</a>></span>= wrote:<br><blockquote class=3D"gmail_quote" style=3D"margin:0 0 0 .8ex;bor= der-left:1px #ccc solid;padding-left:1ex"> It's quiet here- I'd like to stir up some discussion...<br> <br> Thoughts on IPv6?<br> Thoughts on "Cloud Firewalls?"<br> Thoughts on Web Application Firewalls?<br> <br> Paul<br> ______________________________<u></u>_________________<br> firewall-wizards mailing list<br> <a href=3D"mailto:[email protected]" target=3D"_blank"= >firewall-wizards@listserv.<u></u>icsalabs.com</a><br> <a href=3D"https://listserv.icsalabs.com/mailman/listinfo/firewall-wizards"= target=3D"_blank">https://listserv.icsalabs.com/<u></u>mailman/listinfo/fi= rewall-<u></u>wizards</a><br> </blockquote></div><br></div> --089e013c6d9ec95fff04fc8b6421-- --===============0118272959== Content-Type: text/plain; charset="us-ascii" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit Content-Disposition: inline _______________________________________________ firewall-wizards mailing list [email protected] https://listserv.icsalabs.com/mailman/listinfo/firewall-wizards --===============0118272959==--