Re: letting traffic flow through a SG by default
Henry Spencer <[email protected]> Wed, 12 Mar 2003 13:06:32 -0500 (EST)
| Newsgroups | gmane.network.freeswan.devel |
|---|---|
| Message-ID | <[email protected]> |
On Wed, 12 Mar 2003, John S. Denker wrote:
> > Add to the manual: A security gateway is NOT A FIREWALL.
>
> How do you know a security gateway is not a firewall? ...
> Who is to say that I may not choose my security policy, as expressed
> in the SPD, to implement firewall-like functions?
A while back I expressed my understanding of this on the IPsec mailing
list:
IPsec, being about IP *security*, not just IP encryption and
authentication, includes a specification for minimal firewall
functionality, since that is a necessary part of secure IP.
Implementations are, of course, free to provide more sophisticated
firewall mechanisms...
I accompanied that with a grumble that RFC 2401 doesn't explain this
properly. Steve Kent promptly asked if he could use my wording in the
next version of 2401.
The SPD *is* a firewall mechanism, by deliberate intent. Whether any
particular implementation of it has adequate functionality to be your
only firewall mechanism is a separate question.
Henry Spencer
[email protected]