Firewall Wizards mailing list archives

Re: Air Gap vs. firewall


From: "Marcus J. Ranum" <mjr () nfr net>
Date: Fri, 22 Sep 2000 20:11:02 -0400


"A firewall is the logical disconnection of two physically connected net works, while a gap is a physical disconnection of two logically connected networks."

If you can surf the web or get E-mail through it, it's a firewall.

There've been a number of firewalls billed as "air gap" that are
actually involved proxies in which traffic is gatewayed over
some means other than a network (e.g.: a private bus) and/or
packets (e.g.: some kind of de-encapsulation re-encapsulation)
but the bottom line is that if you can surf the web through it,
or get E-mail you're probably not much more secure than with a
conventional firewall.

mjr.
---
Marcus J. Ranum     Chief Technology Officer, Network Flight Recorder, Inc.
Work: http://www.nfr.net
Play: http://pubweb.nfr.net/~mjr


_______________________________________________
Firewall-wizards mailing list
Firewall-wizards () nfr net
http://www.nfr.net/mailman/listinfo/firewall-wizards


Current thread: