Re: letting traffic flow through a SG by default

Henry Spencer <[email protected]> Wed, 12 Mar 2003 13:06:32 -0500 (EST)
Newsgroups gmane.network.freeswan.devel
Message-ID <[email protected]>
On Wed, 12 Mar 2003, John S. Denker wrote:
>  > Add to the manual: A security gateway is NOT A FIREWALL.
> 
> How do you know a security gateway is not a firewall? ...
> Who is to say that I may not choose my security policy, as expressed
> in the SPD, to implement firewall-like functions?

A while back I expressed my understanding of this on the IPsec mailing
list: 

  IPsec, being about IP *security*, not just IP encryption and 
  authentication, includes a specification for minimal firewall 
  functionality, since that is a necessary part of secure IP.  
  Implementations are, of course, free to provide more sophisticated 
  firewall mechanisms...

I accompanied that with a grumble that RFC 2401 doesn't explain this
properly.  Steve Kent promptly asked if he could use my wording in the
next version of 2401.

The SPD *is* a firewall mechanism, by deliberate intent.  Whether any
particular implementation of it has adequate functionality to be your
only firewall mechanism is a separate question.

                                                          Henry Spencer
                                                       [email protected]